I am trying to parse this logs using grok parser in datadog:
2022-04-26T08:10:17.545Z Finished activating shceme {"traceId":"xxxx","timestamp":"2022-05-01T14:39:57.340Z","payload":{"id":"xxx","name":"xxxx","description":"","featureType":"BOOLEAN","meterType":"None","unit":null,"units":null,"status":"NEW","type":"feature.created","webhooks":[]},"messageType":"FEATURE_CREATED"}
The rule I use:
ParsingRule %{notSpace:date} %{data:process_finished} %{data::json}
The result I expect:
{
"traceId": "xxxx",
"timestamp": "2022-05-01T14:39:57.340Z",
"messageType": "FEATURE_CREATED",
"process_finished": "activating scheme",
"date": "2022-04-26T08:10:17.545Z",
"payload": {
"status": "NEW",
"featureType": "BOOLEAN",
"name": "xxxx",
"meterType": "None",
"type": "feature.created",
"id": "feature-analytics",
"description": ""
}
}
The result I get:
{
"date": "2022-04-26T08:10:17.545Z",
"process_started": "\u001bFinished"
}
does anyone knows what is wrong with my grok parsing rule?