Skip to content

Instantly share code, notes, and snippets.

@cdenneen
Created August 6, 2013 18:32
Show Gist options
  • Save cdenneen/6167233 to your computer and use it in GitHub Desktop.
Save cdenneen/6167233 to your computer and use it in GitHub Desktop.
input {
tcp {
port => 3515
type => json
format => json
}
}
filter {
mutate {
type => json
gsub => [
"datetime", "[ \t]$", "",
"process", "[ \t]{2,}", "",
"area", "[ \t]{2,}", "",
"category", "[ \t]{2,}", "",
"level", "[ \t]{2,}", ""
]
}
date {
match => [ "datetime", "MM/dd/YYYY HH:mm:ss.SS" ]
}
mutate {
type => json
rename => [ "message", "@message" ]
add_tag => "%{app}"
add_tag => "%{tags}"
}
mutate {
remove => [ "SourceModuleName", "SourceModuleType", "EventReceivedTime", "tags", "app", "datetime" ]
}
}
output {
stdout { debug => true }
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment