crowdsec/pkg/parser/tests/base-grok/base-grok.yaml

15 lines
295 B
YAML
Raw Normal View History

2020-05-15 09:39:16 +00:00
filter: "evt.Line.Labels.type == 'testlog'"
debug: true
onsuccess: next_stage
name: tests/base-grok
pattern_syntax:
2020-05-24 10:44:33 +00:00
MYCAP1: ".*"
2020-05-15 09:39:16 +00:00
nodes:
- grok:
2020-05-24 10:44:33 +00:00
pattern: ^xxheader %{MYCAP1:extracted_value} trailing stuff$
2020-05-15 09:39:16 +00:00
apply_on: Line.Raw
statics:
- meta: log_type
value: parsed_testlog