You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

6 lines
246 B

#Transform pour FH aviat
[force_sourcetype_for_aviat]
DEST_KEY = MetaData:Sourcetype
FORMAT = sourcetype::aviat
REGEX = (?<device_time>\w+\s+\d{1,2}\s+\d{2}:\d{2}:\d{2}) (?<reported_ip>\S+) (?<user>[^\[]+)\[(?<pid>\d+)\] (?<message_text>.+)