Skip to content

Instantly share code, notes, and snippets.

@rebx
Created September 26, 2013 00:28
Show Gist options
  • Save rebx/6708199 to your computer and use it in GitHub Desktop.
Save rebx/6708199 to your computer and use it in GitHub Desktop.
grok syslogtimestamp + year pattern
# added year to SYSLOGTIMESTAMP
SYSLOGTIMESTAMPYEAR %{MONTH} %{MONTHDAY} %{YEAR} %{TIME}
SYSLOGBACKFILLYEAR %{SYSLOGTIMESTAMPYEAR:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{PROG:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment