input {
file {
path=>["/app/logs/rce-server.inst-2/rce-server.log*"]
type=>"xypp-rce-xxx"
codec => multiline {
# Grok pattern names are valid! :)
pattern => "^\[%{YEAR}%{MONTHNUM}%{MONTHDAY}[- ]%{TIME}"
negate => true
what => previous
}
}
}
filter {
mutate {
add_field =>["newmessage","%{type}_%{message}"]
}
}
filter {
mutate {
remove_field =>["message"]
}