crowdsec/pkg/parser/tests/base-grok-expression/base-grok.yaml
Thibault "bui" Koechlin 7f0cac8ee6
add support for 'expression' (fix #822) in grok patterns (#830)
* add support for 'expression' (fix #822) in grok patterns

* add tests
2021-06-21 09:07:33 +02:00

14 lines
300 B
YAML

filter: "evt.Line.Labels.type == 'testlog'"
debug: true
onsuccess: next_stage
name: tests/base-grok
pattern_syntax:
MYCAP1: ".*"
nodes:
- grok:
pattern: ^xxheader %{MYCAP1:extracted_value} trailing stuff$
expression: evt.Line.Raw
statics:
- meta: log_type
value: parsed_testlog