Grok parser for my below stuff not working


(Blason) #1

HI Team,

I am trying to parse below line but seems this is not working. Can someone please help?

[2018-11-10 12:48:04] [2236] [http_80_tcp 3327] [192.168.1.2:53234] info: Request URL: http://192.168.1.39/test.doc

%{TIME:TIME}%{SPACE:SPACE}%{INT:port}


(Blason) #2

OK I managed to resovle it…


(Jan Doberstein) #3

sharing might be helpful for others - thank you.


(Blason) #4

Oh sure, will share the parser.


(Blason) #5

Here was the parser

   %{TIME:TIME}\] \[%{INT:PID}\] \[%{WORD:PORT} %{WORD:IGNORE}\] \[%{IPV4:IP}:%{INT:SRCPORT}\] %{WORD:TYPE}: %{WORD:METHOD} %{WORD:RESOURCE}: %{URI:URL}