
This adds the ability to include logstash log parsing filters for various openstack and service logs. These filters are disabled by default and can be enabled by toggling the deploy_logstash_filters variable. Change-Id: I5c46f78f232d3fb604283ae623cd3975a8346c7c
11 lines
278 B
Plaintext
11 lines
278 B
Plaintext
filter {
|
|
if "auth" in [tags] {
|
|
grok {
|
|
match => { "message" => "%{SYSLOGTIMESTAMP:timestamp} (?:%{SYSLOGFACILITY} )?%{NOTSPACE:logsource} %{SYSLOGPROG}: (?:%{SPACE})?%{GREEDYDATA:logmessage}" }
|
|
}
|
|
mutate {
|
|
add_field => { "module" => "auth" }
|
|
}
|
|
}
|
|
}
|