apply: true
sudo: true
+logstash::drop_grokparsefailure: false
logstash::generic_resource:
docmorris_factfinder:
resource: file
- "docmorris-ff7"
- "%{customer}"
- "%{environment}"
+ ff_filter:
+ resource: grok
+ order: 40
+ condition: "if [type] == 'tomcat'"
+ parameters:
+ match:
+ - "message"
+ - '%%{ich-trickse}{IP:ip}%%{ich-trickse}{SPACE}\[%%{ich-trickse}{HTTPDATE:logdate}%%{ich-trickse}{DATA}%%{ich-trickse}{QS:request}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:status}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:size}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:time}'
apply: true
sudo: true
+logstash::drop_grokparsefailure: false
logstash::generic_resource:
docmorris_factfinder:
resource: file
- "docmorris-ff7"
- "%{customer}"
- "%{environment}"
+ ff_filter:
+ resource: grok
+ order: 40
+ condition: "if [type] == 'tomcat'"
+ parameters:
+ match:
+ - "message"
+ - '%%{ich-trickse}{IP:ip}%%{ich-trickse}{SPACE}\[%%{ich-trickse}{HTTPDATE:logdate}%%{ich-trickse}{DATA}%%{ich-trickse}{QS:request}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:status}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:size}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:time}'
apply: true
sudo: true
+logstash::drop_grokparsefailure: false
logstash::generic_resource:
docmorris_factfinder:
resource: file
- "docmorris-ff7"
- "%{customer}"
- "%{environment}"
+ ff_filter:
+ resource: grok
+ order: 40
+ condition: "if [type] == 'tomcat'"
+ parameters:
+ match:
+ - "message"
+ - '%%{ich-trickse}{IP:ip}%%{ich-trickse}{SPACE}\[%%{ich-trickse}{HTTPDATE:logdate}%%{ich-trickse}{DATA}%%{ich-trickse}{QS:request}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:status}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:size}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:time}'
parameters:
match:
- "message"
- - '%%{ich-trickse}{IP:ip}%%{ich-trickse}{SPACE}\[%%{ich-trickse}{HTTPDATE:logdate}%%{ich-trickse}{DATA}%%{ich-trickse}{QS:request}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:status}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:length}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:time}'
\ No newline at end of file
+ - '%%{ich-trickse}{IP:ip}%%{ich-trickse}{SPACE}\[%%{ich-trickse}{HTTPDATE:logdate}%%{ich-trickse}{DATA}%%{ich-trickse}{QS:request}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:status}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:size}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:time}'
apply: true
sudo: true
+logstash::drop_grokparsefailure: false
logstash::generic_resource:
docmorris_factfinder01:
resource: file
- "docmorris-ff7"
- "%{customer}"
- "%{environment}"
+ ff_filter:
+ resource: grok
+ order: 40
+ condition: "if [type] == 'tomcat'"
+ parameters:
+ match:
+ - "message"
+ - '%%{ich-trickse}{IP:ip}%%{ich-trickse}{SPACE}\[%%{ich-trickse}{HTTPDATE:logdate}%%{ich-trickse}{DATA}%%{ich-trickse}{QS:request}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:status}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:size}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:time}'
apply: true
sudo: true
+logstash::drop_grokparsefailure: false
logstash::generic_resource:
docmorris_factfinder:
resource: file
- "docmorris-ff7"
- "%{customer}"
- "%{environment}"
+ ff_filter:
+ resource: grok
+ order: 40
+ condition: "if [type] == 'tomcat'"
+ parameters:
+ match:
+ - "message"
+ - '%%{ich-trickse}{IP:ip}%%{ich-trickse}{SPACE}\[%%{ich-trickse}{HTTPDATE:logdate}%%{ich-trickse}{DATA}%%{ich-trickse}{QS:request}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:status}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:size}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:time}'
apply: true
sudo: true
+logstash::drop_grokparsefailure: false
logstash::generic_resource:
docmorris_factfinder01:
resource: file
- "docmorris-ff7"
- "%{customer}"
- "%{environment}"
+ ff_filter:
+ resource: grok
+ order: 40
+ condition: "if [type] == 'tomcat'"
+ parameters:
+ match:
+ - "message"
+ - '%%{ich-trickse}{IP:ip}%%{ich-trickse}{SPACE}\[%%{ich-trickse}{HTTPDATE:logdate}%%{ich-trickse}{DATA}%%{ich-trickse}{QS:request}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:status}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:size}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:time}'
apply: true
sudo: true
+logstash::drop_grokparsefailure: false
logstash::generic_resource:
docmorris_factfinder01:
resource: file
- "docmorris-ff7"
- "%{customer}"
- "%{environment}"
+ ff_filter:
+ resource: grok
+ order: 40
+ condition: "if [type] == 'tomcat'"
+ parameters:
+ match:
+ - "message"
+ - '%%{ich-trickse}{IP:ip}%%{ich-trickse}{SPACE}\[%%{ich-trickse}{HTTPDATE:logdate}%%{ich-trickse}{DATA}%%{ich-trickse}{QS:request}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:status}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:size}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:time}'
apply: true
sudo: true
+logstash::drop_grokparsefailure: false
logstash::generic_resource:
docmorris_factfinder:
resource: file
- "docmorris-ff7"
- "%{customer}"
- "%{environment}"
+ ff_filter:
+ resource: grok
+ order: 40
+ condition: "if [type] == 'tomcat'"
+ parameters:
+ match:
+ - "message"
+ - '%%{ich-trickse}{IP:ip}%%{ich-trickse}{SPACE}\[%%{ich-trickse}{HTTPDATE:logdate}%%{ich-trickse}{DATA}%%{ich-trickse}{QS:request}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:status}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:size}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:time}'
apply: true
sudo: true
+logstash::drop_grokparsefailure: false
logstash::generic_resource:
docmorris_factfinder:
resource: file
- "docmorris-ff7"
- "%{customer}"
- "%{environment}"
+ ff_filter:
+ resource: grok
+ order: 40
+ condition: "if [type] == 'tomcat'"
+ parameters:
+ match:
+ - "message"
+ - '%%{ich-trickse}{IP:ip}%%{ich-trickse}{SPACE}\[%%{ich-trickse}{HTTPDATE:logdate}%%{ich-trickse}{DATA}%%{ich-trickse}{QS:request}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:status}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:size}%%{ich-trickse}{DATA}%%{ich-trickse}{NUMBER:time}'
+