Refinement on my working grok pattern for multiline javastack logs

Viewed 41

My log file has numerous spaces and new line characters, I have written grok pattern to extract data from it. Need some confirmation if this approach is good for this kind of logs of if there is any other better approach please suggest.

Original Log file:

Active: 37 minutes  0.00 seconds 
  User:
    ServiceUser1
  Tenant:
    
  Session:
    9F0071A66D89544155D149CCE2453E9A:mx2135649930e123d964:(WebServiceFacade.java:84)
  Parameters:
    bosContext _cntx:
      user:
        ContextUser1
      depth:
        3
      session id:
        9F0071A66D89544155D149CCE2453E9A:mx2135649930e123d964:(WebServiceFacade.java:84)
    bosUTF _className:
      TestClassName1
    bosStringList _construct:
      2 entries
          $$MXRIP$$|java.util.HashMap
          1
    bosUTF _methodName:
      TestMethodName1

Working Grok for above log without spaces is this.

Active:((?m))%{GREEDYDATA:Active}\n\s*User\:\n((?m))%{GREEDYDATA:User}\n\s*Tenant:\n((?m))%{GREEDYDATA:Tenant}\n\s*Session:\n((?m))%{DATA:session}\n\s*Parameters:\n\s*bosContext\s_cntx:\n\s*user:\n((?m))%{GREEDYDATA:ContextUser}\n\s*depth:\n((?m))%{GREEDYDATA:depth}\n\s*session\sid:\n((?m))%{GREEDYDATA:SessionID}\n\s*bosUTF\s_className:\n((?m))%{DATA:ClassName}\n\s*bosStringList\s_construct:\n((?m))%{GREEDYDATA:Construct}\n\s*bosUTF\s_methodName:\n((?m))%{GREEDYDATA:Method}

Is it really good approach to write this many spaces and GREEDYDATA in grok pattern. Please confirm.

0 Answers
Related