File tree Expand file tree Collapse file tree 1 file changed +3
-3
lines changed
_ingest-pipelines/processors Expand file tree Collapse file tree 1 file changed +3
-3
lines changed Original file line number Diff line number Diff line change @@ -71,7 +71,7 @@ PUT _ingest/pipeline/log_line
7171 {
7272 "grok" : {
7373 "field" : " message" ,
74- "patterns" : [" %{IPORHOST:clientip} %{HTTPDATE:timestamp} %{NUMBER:response_status:int}" ]
74+ "patterns" : [" ^ %{IPORHOST:clientip} %{HTTPDATE:timestamp} %{NUMBER:response_status:int}" ]
7575 }
7676 }
7777 ]
@@ -160,7 +160,7 @@ PUT _ingest/pipeline/log_line
160160 {
161161 "grok" : {
162162 "field" : " message" ,
163- "patterns" : [" The issue number %{NUMBER:issue_number} is %{STATUS:status}" ],
163+ "patterns" : [" ^ The issue number %{NUMBER:issue_number} is %{STATUS:status}" ],
164164 "pattern_definitions" : {
165165 "NUMBER" : " \\ d{3,4}" ,
166166 "STATUS" : " open|closed"
@@ -184,7 +184,7 @@ PUT _ingest/pipeline/log_line
184184 {
185185 "grok" : {
186186 "field" : " message" ,
187- "patterns" : [" %{HTTPDATE:timestamp} %{IPORHOST:clientip}" , " %{IPORHOST:clientip} %{HTTPDATE:timestamp} %{NUMBER:response_status:int}" ],
187+ "patterns" : [" ^ %{HTTPDATE:timestamp} %{IPORHOST:clientip}" , " %{IPORHOST:clientip} %{HTTPDATE:timestamp} %{NUMBER:response_status:int}" ],
188188 "trace_match" : true
189189 }
190190 }
You can’t perform that action at this time.
0 commit comments