-1
07:40:28,339 INFO  [org.sprinframework.web.context.ContxtLoader] (ServerService Thread Pool -- 672)  WebApplicationContext: initialization started

我写了这样的模式

grok { 
      match => { "message" => "%{TIME:timestamp}%{SPACE}%{WORD:loglevel}%{SPACE}%{DATA:classname}%{SPACE}%{DATA:url}{THREADPOOL:thread}%{SPACE}%{DATA:logs}" }

}
4

1 回答 1

0

您需要的 grok 模式是:

%{TIME:timestamp}%{SPACE}%{LOGLEVEL:level}%{SPACE}\[(?<logger>[^\]]+)\]%{SPACE}\((?<thread>[^)]+)\)%{SPACE}%{GREEDYDATA:message}
于 2016-01-22T12:32:15.523 回答