Grok Parsing a log file with nested JSON

Viewed 192

I'm trying to use a Grok parser (inside of Datadog's Logs service) to extract the json key:values in the following log lines (dont worry, I randomized some of the values):

[INFO]  2021-08-09T23:20:48.282Z    49be9ba-000c-4d90-1011-10101001 Received event: {"PayloadData": "Yq==", "WirelessDeviceId": "abcd1234-abc12-3456-78910-abc9adkasd", "WirelessMetadata": {"LoRaWAN": {"ADR": true, "Bandwidth": 125, "ClassB": false, "CodeRate": "4/5", "DataRate": "3", "DevAddr": "019cf43e", "DevEui": "844oda0000006a80", "FCnt": 2530, "FOptLen": 0, "FPort": 10, "Frequency": "903900000", "Gateways": [{"GatewayEui": "abc123fffp09fd12", "Rssi": -102, "Snr": 8}], "MIC": "31p41ed2", "MType": "UnconfirmedDataUp", "Major": "LoRaWANR1", "Modulation": "LORA", "PolarizationInversion": false, "SpreadingFactor": 7, "Timestamp": "2021-08-09T23:20:47Z"}}}

But I can't quite figure out how to do it properly. Grok feels very tedious and fragile. The format of the logs remain the same as above, but obviously the values are constantly changing.

Any recommendations on how to get started down the right path?

0 Answers
Related