Skip to content

Instantly share code, notes, and snippets.

@jsvd
Last active November 15, 2019 13:11
Show Gist options
  • Save jsvd/23dbb156904e9ba770d48bb971b6735e to your computer and use it in GitHub Desktop.
Save jsvd/23dbb156904e9ba770d48bb971b6735e to your computer and use it in GitHub Desktop.
input {
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
}
filter {
grok {
timeout_grouped => true
match => { "message" => [
"^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$",
"^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$",
"^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$",
"^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$",
"^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$",
"^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$", "^%{WORD}$",
"^%{NUMBER}$"
] }
}
}
output { stdout { codec => dots }}
input {
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
generator { message => "!" }
}
filter {
grok {
timeout_grouped => true
match => { "message" => [ "^%{WORD}$" ] }
}
}
output { stdout { codec => dots }}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment