我想删除
" "
来自此消息。
< 189> date = 2018-03-02 time = 00:50:16 devname =" TEST" DEVID =" AAAAA" LOGID =" 0000000013"类型="流量" 亚型="向前"级="通知" VD ="根" EVENTTIME = 1519980616 srcip = 111.111.111 srcport = 12345 srcintf =" AAAAA" srcintfrole ="兰" dstip = AAAAAAA dstport = 443 dstintf =" port1" dstintfrole ="未定义" poluuid =" 52b23c9c-126C-51e8-84e1-38a5953285dc" sessionid = 57002479 proto = 17 action =" accept"策略ID = 62 的PolicyType ="策略"服务=" UDP_443" dstcountry ="美国" srccountry ="保留" trandisp =" SNAT" transip = 123.123.123.123 transport = 55699 duration = 181 sentbyte = 4928 rcvdbyte = 5026 sentpkt = 9 rcvdpkt = 10 appcat ="未扫描"
我有这个过滤器:
grok {
match => ["message", "%{SYSLOG5424PRI:syslog_index}%{GREEDYDATA:message}"]
overwrite => [ "message" ]
tag_on_failure => [ "failure" ]
}
kv { }