I am exploring graylog…I have usecase where I have logfiles(generated from multiple sources) available in my system. I need to parse them and log files have following format
- each log message is separated by ‘|’
- we have standardized the fields/columns for logged messages, but their order can change among different files. So we are maintaining first line in each log file as header which is also separated with “|”
there are a lot of option available but not sure which will work, so it will be helpful if I get guidance on this on how we can achieve this
Note : Dashboarding will done on the resultant fields
Please post example of message and header, and which method (type of Input) do you use to ingest.
thank you @shoothub for replying…
folowing is the sample logfile content
2020-04-10 17:14:05|INFO|User Authentication|ogin|Success|Configuration /admin activity done: User login attempt with credentials has success|admin/login|200|
|INFO|User Authentication|Login|Success|Configuration /admin activity done: User login attempt with credentials has success|admin/login|200|
I am using Sidecar for collecting data using filebeat
This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.