Skip to content

Conversation

cosmo0920
Copy link
Collaborator

@cosmo0920 cosmo0920 commented Oct 12, 2021

logstash-patterns-core starts to provide Elastic Common Schema (ECS) v1 compatible grok patterns.
fluent-plugin-grok-parser also should provide such grok patterns.

For backward compatibility, we specify the legacy ones by default.

Signed-off-by: Hiroshi Hatake <hatake@calyptia.com>
Signed-off-by: Hiroshi Hatake <hatake@calyptia.com>
Signed-off-by: Hiroshi Hatake <hatake@calyptia.com>
Signed-off-by: Hiroshi Hatake <hatake@calyptia.com>
Signed-off-by: Hiroshi Hatake <hatake@calyptia.com>
@cosmo0920 cosmo0920 requested review from ashie and kenhys October 12, 2021 06:43
@cosmo0920 cosmo0920 self-assigned this Oct 12, 2021
Signed-off-by: Hiroshi Hatake <hatake@calyptia.com>
@cosmo0920 cosmo0920 marked this pull request as draft October 13, 2021 05:14
@cosmo0920
Copy link
Collaborator Author

cosmo0920 commented Oct 13, 2021

I've found that ecs-v1 version of grok pattern is not usable with current format on Fluentd.
We need to investigate how it works further.

Signed-off-by: Hiroshi Hatake <hatake@calyptia.com>
@cosmo0920 cosmo0920 marked this pull request as ready for review October 13, 2021 06:43
@cosmo0920
Copy link
Collaborator Author

cosmo0920 commented Oct 13, 2021

I've found that ecs-v1 version of grok pattern is not usable with current format on Fluentd.
We need to investigate how it works further.

Now, fixed.

@ashie
Copy link
Member

ashie commented Jan 27, 2022

Oops, sorry I overlooked this until now...

Copy link

@kenhys kenhys left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@cosmo0920 cosmo0920 merged commit 74658f9 into fluent:master Jan 31, 2022
@cosmo0920 cosmo0920 deleted the provide-ecs-v1-grok-patterns branch January 31, 2022 05:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants