Skip to content

Instantly share code, notes, and snippets.

@MichalBryxi
Forked from tkorkunckaya/postfix_patterns
Last active December 17, 2015 14:39
Show Gist options
  • Save MichalBryxi/5626060 to your computer and use it in GitHub Desktop.
Save MichalBryxi/5626060 to your computer and use it in GitHub Desktop.
Logstash indexer config for parsing postfix logs
# We will focus only on how to parse the records
filter {
# Split postfix record to basic parts
grok {
type => 'postfix'
pattern => '%{SYSLOGBASE}'
named_captures_only => true
}
# Split by spaces, trim colons and brackets
kv {
type => 'postfix'
field_split => ' '
trim => '<>,'
source => "@message"
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment