-
hugh_jass has quit
-
hugh_jass joined the channel
-
DevRelIrcBot_ has quit
-
DevRelIrcBot has quit
-
DevRelIrcBot__ has quit
-
DevRelIrcBot____ has quit
-
DevRelIrcBot___ has quit
-
Schwarzbaer_ joined the channel
-
Schwarzbaer has quit
-
tfontaine joined the channel
-
hugh_jass has quit
-
hugh_jass joined the channel
-
pengin has quit
-
pengin joined the channel
-
pengin has quit
-
fev3r101 joined the channel
-
hugh_jass has quit
-
hugh_jass joined the channel
-
pengin joined the channel
-
FreeSpencer joined the channel
-
andrewvc has quit
-
deimos has quit
-
techminer1 has quit
-
Beardless_One has quit
-
justif has quit
-
Xylakant has quit
-
purbon has quit
-
techminer joined the channel
-
peterkimnyc has quit
-
Whisket has quit
-
dino82 has quit
-
thedavisone has quit
-
jthomassie has quit
-
cstrahan has quit
-
gyre007 has quit
-
DandyPandy has quit
-
untergeek has quit
-
FrostyBeverage has quit
-
dino82 joined the channel
-
DandyPandy joined the channel
-
tfontaine has quit
-
jthomassie joined the channel
-
arnonhongklay joined the channel
-
lipoqil joined the channel
-
deimos joined the channel
-
andrewvc joined the channel
-
cstrahan joined the channel
-
gyre007 joined the channel
-
pygirl24 joined the channel
-
peterkimnyc joined the channel
-
Xylakant joined the channel
-
FrostyBeverage joined the channel
-
justif joined the channel
-
purbon joined the channel
-
untergeek joined the channel
-
thedavisone joined the channel
-
Beardless_One joined the channel
-
Whisket joined the channel
-
hugh_jass has quit
-
hugh_jass joined the channel
-
berglh
-
BaM`
been using that for a while - joda parsing does my head in
-
berglh
it's handy
-
got some guys trying to parse some oracle db logs
-
which has month in letters all caps
-
which non of the default logstash patterns detect
-
They do leading capital three letter months
-
aj__ joined the channel
-
turns out joda parses it fine
-
so just needed to get the string into a @metadata field
-
BaM`
we have a cool case here. Hour=[1,24]
-
because the dev thought having 0 for an hour would be confusing
-
pengin has quit
-
and it's in prod, and customers are using the API
-
so it can never be changed
-
I know you can use k for that, but it's still annoying
-
adaam joined the channel
-
hugh_jass has quit
-
hugh_jass joined the channel
-
alduin has quit
-
alduin joined the channel
-
pawnbox joined the channel
-
jerryitt joined the channel
-
ninjada has quit
-
hugh_jass has quit
-
hugh_jass joined the channel
-
dancleinmark joined the channel
-
davidski joined the channel
-
dancleinmark has quit
-
hulu1522 joined the channel
-
brokencycle joined the channel
-
pawnbox joined the channel
-
hulu1522 has quit
-
hugh_jass has quit
-
hugh_jass joined the channel
-
berglh
that's rediculous
-
who thinks of these things
-
hmm.. i guess in the right context
-
1st hour, 2nd hour
-
if you're treating them as buckets
-
dino82 has quit
-
dino82 joined the channel
-
pawnbox joined the channel
-
BaM`
well the numbers for 1-23 are fine. But midnight is never 24 anywhere else - that's the stupid part
-
but not the stupidest part, unfortunately
-
short version - the filter to parse these logs is 300 lines long
-
hugh_jass has quit
-
hugh_jass joined the channel
-
arnonhongklay joined the channel
-
brokencycle has quit
-
geek_cl joined the channel
-
hugh_jass has quit
-
hugh_jass joined the channel
-
arnonhongklay joined the channel
-
vali joined the channel
-
pawnbox joined the channel
-
hugh_jass has quit
-
hugh_jass joined the channel
-
berglh
can't you just gsub ^24: for 00: ?
-
achan joined the channel
-
eitherway, sounds like a pain
-
jerryitt has quit
-
BaM`
berglh: I used so much gsub in these filters even thinking about using it makes me feel dirty now
-
geek_cl has quit
-
but no, joda "k" does the trick anyway
-
it's just super-annoying finding all the uses of it in the logs - you gotta look for the midnight entries
-
also: whyyyyyyy
-
it would be nice if I could say: this log file uses joda k
-
but it's a mish-mash of stuff and there's no consistency
-
I need to parse half the entry out before I can even decide how to parse the date
-
things like KV lines with json in the middle
-
but the KV part doesn't have consistent separators
-
some are commas, some are spaces - on the same line
-
it's the second-worst lot of logs that I've ever dealt with
-
..the worst being one that had miltiline ascii-decorated tables in it
-
*multiline
-
achan1 joined the channel
-
achan has quit
-
berglh
yeah..
-
i feel your pain
-
hugh_jass has quit
-
the kv filed split string should not be a char class, but a regex
-
hugh_jass joined the channel
-
davidski has quit
-
boargod has quit
-
pengin joined the channel
-
boargod joined the channel
-
vali has quit
-
brotatochip joined the channel
-
SkyRocknRoll joined the channel