Hello,
I am trying to create a grok pattern for this kind of message :
[Wed May 20 12:02:23.129491 2020] [php7:notice] [pid 13854:tid 139987422476032] [client 10.151.2.142:48670] Missing circuit id/?!=services|segment|new&circuit_id=999999&ordinal=74, referer https://domain.domain/?!=orders|extended_circuit|view|999999&order_id=8888888 domain.domain
Here is the pattern :
[%{HTTPDERROR_DATE:timestamp_error}] [%{WORD:module_error}:%{LOGLEVEL:loglevel_error}] [pid %{POSINT:pid}:tid %{NUMBER:tid}]( (%{POSINT:proxy_errorcode})%{DATA:proxy_errormessage}:)?( [client %{IPORHOST:client}:%{POSINT:clientport}])? %{DATA:errorcode}: %{GREEDYDATA:message_error} %{IPORHOST:vhost_error}
But I am not able because of the referer.
If no referer, the pattern works.
Can anyone help?
Thanks