Skip to content

Instantly share code, notes, and snippets.

@griggheo
Created August 3, 2015 22:42
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save griggheo/0949feb083df0b6e7afe to your computer and use it in GitHub Desktop.
Save griggheo/0949feb083df0b6e7afe to your computer and use it in GitHub Desktop.
filter {
grok {
add_tag => [ "valid" ]
match => { "message" => "%{APPLOGLINE}" }
}
json {
source => "payload"
}
if "valid" not in [tags] {
drop { }
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment