Skip to content

Commit feac586

Browse files
committed
Grok ingest processor: add anchoring to pattern examples
Signed-off-by: James Beckett <[email protected]>
1 parent 355727a commit feac586

File tree

1 file changed

+3
-3
lines changed
  • _ingest-pipelines/processors

1 file changed

+3
-3
lines changed

_ingest-pipelines/processors/grok.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -71,7 +71,7 @@ PUT _ingest/pipeline/log_line
7171
{
7272
"grok": {
7373
"field": "message",
74-
"patterns": ["%{IPORHOST:clientip} %{HTTPDATE:timestamp} %{NUMBER:response_status:int}"]
74+
"patterns": ["^%{IPORHOST:clientip} %{HTTPDATE:timestamp} %{NUMBER:response_status:int}"]
7575
}
7676
}
7777
]
@@ -160,7 +160,7 @@ PUT _ingest/pipeline/log_line
160160
{
161161
"grok": {
162162
"field": "message",
163-
"patterns": ["The issue number %{NUMBER:issue_number} is %{STATUS:status}"],
163+
"patterns": ["^The issue number %{NUMBER:issue_number} is %{STATUS:status}"],
164164
"pattern_definitions" : {
165165
"NUMBER" : "\\d{3,4}",
166166
"STATUS" : "open|closed"
@@ -184,7 +184,7 @@ PUT _ingest/pipeline/log_line
184184
{
185185
"grok": {
186186
"field": "message",
187-
"patterns": ["%{HTTPDATE:timestamp} %{IPORHOST:clientip}", "%{IPORHOST:clientip} %{HTTPDATE:timestamp} %{NUMBER:response_status:int}"],
187+
"patterns": ["^%{HTTPDATE:timestamp} %{IPORHOST:clientip}", "%{IPORHOST:clientip} %{HTTPDATE:timestamp} %{NUMBER:response_status:int}"],
188188
"trace_match": true
189189
}
190190
}

0 commit comments

Comments
 (0)