12:38 PM
jsm-oxa
12:39 PM
electrical
vks: you will need to set negate to true ( so it does a grep -v ) and set drop to false . then you need to set the pattern to something you don't want parsing to happen.. and set add_tag to a tag. and let the other filters only react on that tag.
12:40 PM
vks
i had done that
12:40 PM
lbjay_ is now known as lbjay
12:40 PM
need to verify once more
12:41 PM
electrical
vks, okay. can you pastie/pastebin/gist your config so i can take a look?
12:41 PM
vks
ok
12:42 PM
BlackMaria joined the channel
12:44 PM
12:44 PM
logstashbot
12:44 PM
vks
electrical
12:44 PM
zdunn joined the channel
12:44 PM
i am getting _grokparsefailure when TenantId: pattern is there
12:45 PM
electrical
okay. in your first grep, you need to set drop to false.. because it defaults to true ( so it will drop the event )
12:46 PM
vks
sorry the case is same for drop => false
12:46 PM
postwait has quit
12:47 PM
electrical
okay
12:47 PM
looks all good then. could you also paste some example logs for both cases?
12:48 PM
tziOm joined the channel
12:48 PM
errordeveloper has quit
12:48 PM
vks
12:48 PM
logstashbot
12:48 PM
vks
u can see the @tags
12:49 PM
currently i am doing output to stdout
12:49 PM
electrical
yeah. so its failing on the second part
12:49 PM
vks
which means after matching for first grep
12:50 PM
it is going to match second one
12:50 PM
and there it is getting _grokparsefailure
12:50 PM
so how to deal with that??
12:50 PM
errordeveloper joined the channel
12:50 PM
electrical
yeah. but for some reason it doesn't match the grok pattern indeed. can you paste the whole log entry its failing on? ( ps. i need to leave in 10 minutes, but will be back online later )
12:52 PM
vks
electrical i am jar file directly and hadn't set any log file. Does logstash by default create the log file
12:52 PM
cjs226 joined the channel
12:52 PM
electrical
vks, i mean part of the log you are trying to parse :-)
12:53 PM
vks
12:53 PM
logstashbot
12:53 PM
vks
u can see the log output
12:55 PM
if this is not the way then how we can match the multiple pattern
12:57 PM
jonconley
Does whack do sponsored development?
12:58 PM
electrical
jonconley, how do you mean? sponsored development?
12:58 PM
jonconley
12:58 PM
logstashbot
Title: Homepage of Zabbix :: An Enterprise-Class Open Source Distributed Monitoring Solution (at
www.zabbix.com )
12:59 PM
jsm-oxa has quit
12:59 PM
jonconley
So, if you want a feature, you spec it out, he tells you what he can/can't do and the cost.
12:59 PM
Community can crowdsource it
12:59 PM
Or a company can just foot the bill themselves, like mine
12:59 PM
electrical
might be something he could consider but not sure.
13:00 PM
jonconley
and he is the sole developer correct? or 99% of the code is him?
13:00 PM
electrical
he should be online in 2-4 hours or so. you can ask him
13:00 PM
jonconley
ok, thanks electrical
13:00 PM
electrical
np
13:00 PM
vks
electrical any idea??
13:00 PM
dblessing joined the channel
13:01 PM
electrical
vks, not sure. will need to double check later when i'm home.
13:01 PM
vks
ok
13:01 PM
thnx
13:01 PM
Jahkeup_ joined the channel
13:01 PM
electrical
please ping me when i'm online again later.
13:05 PM
eper joined the channel
13:05 PM
dyer joined the channel
13:07 PM
jedi4ever joined the channel
13:08 PM
threesome has quit
13:13 PM
spryfox joined the channel
13:14 PM
berkay2 joined the channel
13:14 PM
electrical has quit
13:17 PM
cnb_ has quit
13:17 PM
berkay has quit
13:17 PM
jeebus268 joined the channel
13:19 PM
BryanWB__ joined the channel
13:22 PM
vks
how can we deal with multiple pattern in logstash??
13:23 PM
Kubes_ joined the channel
13:23 PM
h0cin joined the channel
13:25 PM
zdunn has quit
13:29 PM
feylya
vks: what do you mean?
13:29 PM
vks
13:29 PM
logstashbot
13:30 PM
vks
feylya
13:30 PM
i had sent u conf file
13:30 PM
feylya
what are you trying to achieve?
13:32 PM
mbaxa joined the channel
13:32 PM
stackedsax1 joined the channel
13:37 PM
h0cin has quit
13:40 PM
vks
feylya: i am lookin for the word TenantId i need to use one grok pattern and if it is not there it had to use second grok pattern
13:42 PM
feylya has quit
13:44 PM
kjstone00 joined the channel
13:46 PM
h0cin joined the channel
13:47 PM
bfulton joined the channel
13:49 PM
bodik???
13:49 PM
neur0x joined the channel
13:49 PM
neur0x has quit
13:49 PM
neur0x joined the channel
13:50 PM
postwait joined the channel
13:50 PM
bodik
yes
13:50 PM
feylya joined the channel
13:51 PM
cbarraford|away is now known as cbarraford
13:52 PM
neur0x has quit
13:52 PM
feylya
vks: you can use multiple patterns in the same grok filter
13:53 PM
vks
can u explain a bit???
13:53 PM
13:53 PM
logstashbot
13:53 PM
feylya
what needs to be explained?
13:56 PM
vks
my requirment is If the message has "TenantId" use pattern "XYZ" else if message has "ABC" use pattern "PQR" else use pattern "RTY" . U can have a look of on my conf file , how i have done
13:56 PM
csd126 has quit
13:56 PM
13:56 PM
logstashbot
13:57 PM
trahma joined the channel
13:57 PM
csd126 joined the channel
13:58 PM
feylya
so what's not working?
13:58 PM
bodik
"tenant_id":["c701192b-fcad-4378-995d-f9dc05747aa4"],"received_at":["2013-05-31T12:40:23.729Z"],
13:58 PM
where's the problem ?
13:58 PM
probably you mean where the _grokparsefail is comming from ?
14:01 PM
goran2 has quit
14:01 PM
pablo_ has quit
14:04 PM
so ?
14:04 PM
what's the problem >/
14:04 PM
?
14:04 PM
threesome joined the channel
14:07 PM
vks
bodik: yes _grokparsefailure is coming
14:08 PM
pablo_ joined the channel
14:08 PM
kjstone00 has quit
14:08 PM
and that also b'coz it try to parse the second pattern
14:08 PM
edehde has left the channel
14:09 PM
alistar joined the channel
14:09 PM
feylya
does that matter?
14:10 PM
Jahkeup_ has quit
14:10 PM
Oxtiax has quit
14:11 PM
davetoo joined the channel
14:11 PM
Jahkeup_ joined the channel
14:12 PM
ScottG489
test
14:12 PM
tombar has quit
14:13 PM
bodik
vks: from that last grok
14:13 PM
davetoo
passwed
14:13 PM
passed, too
14:13 PM
bodik
cause filter without type, or exclude_tags or tags will handle every message
14:14 PM
so if you want to have final else you probably need to make some exclustion or more add_tag-or-remove_tag--magic-here
14:14 PM
imho, i've never done this yet
14:16 PM
could be ?
14:17 PM
_maes_ has quit
14:19 PM
wimvandijck joined the channel
14:19 PM
_maes_ joined the channel
14:19 PM
kimchy has quit
14:23 PM
MrBIOS joined the channel
14:23 PM
kimchy joined the channel
14:24 PM
jeebus268 has quit
14:24 PM
jeebus268 joined the channel
14:24 PM
logstashbot
14:25 PM
_maes_ has quit
14:25 PM
mortini
hm
14:27 PM
ggoZ joined the channel
14:29 PM
rashidkpc joined the channel