parameters:
match:
- message
- - '\[%%{ich-trickse}{MONTHDAY}-%%{ich-trickse}{MONTH}-%%{ich-trickse}{YEAR} %%{ich-trickse}{TIME}\] %%{ich-trickse}{LOGLEVEL:loglevel}\: %%{ich-trickse}{GREEDYDATA:restmessage}'
+ - '\[%%{ich-trickse}{MONTHDAY}-%%{ich-trickse}{MONTH}-%%{ich-trickse}{YEAR} %%{ich-trickse}{TIME}%%{ich-trickse}{SPACE}%%{ich-trickse}{GREEDYDATA:timezone}?\] %%{ich-trickse}{LOGLEVEL:loglevel}?[ :]*%%{ich-trickse}{GREEDYDATA:restmessage}'
php_fpm_slow_filter:
condition: 'if [type] == "php-fpm-slow"'
resource: grok