카테고리 : IT2/elk stack buytime | 2023. 2. 1. 20:11
# NAC 5.0 버전 [INPUT] input { udp { port => 5514 } } [FILTER] filter { grok { match => { "message" => "\%{TIMESTAMP_ISO8601:_datetime} %{LOGLEVEL:_logtype} %{INT:_logid} %{DATA:_sensorname} %{DATA:_ip} %{DATA:_mac} %{DATA:detailmsg} %{GREEDYDATA:_fullmsg}" } } mutate { gsub => ["_fullmsg"," NONE",". "] gsub => ["_fullmsg","NONE ",""] } mutate { split => ["_fullmsg",". "] add_field => { "_fullmsg_..