Add grok pattern to parse Docker logs and remove unnecessary field

Signed-off-by: Johann Hoffmann <johann.hoffmann@mailbox.org>
This commit is contained in:
Johann Hoffmann
2022-05-16 17:30:31 +02:00
parent 1a90446115
commit 3b5a2556bd

View File

@@ -697,6 +697,15 @@ releases:
syslog {
tags => ["ucentral-syslog"]
port => 5514
grok_pattern => "(?:<%{POSINT:priority}>%{SYSLOGLINE}|%{MONTH} %{MONTHDAY} %{TIME} %{DATA:docker.container_name}/%{DATA:github.run_number}\[%{INT:undefined_number}\]: %{GREEDYDATA:message})"
}
}
filter {
if ([undefined_number]) {
mutate {
remove_field => [ "undefined_number" ]
}
}
}