Reputation: 1
I have a message with multi-lines need to match using Grok. Can everyone help me check and correct my grok below. Thanks
Log message:
"[timestamp: 1621431760] abort handler of pid 1823 thread 1848977280
*** Stacks of threads *** (current thread is 1848977280)
Stack of thread=1848977280, depth=3 main
shutdownServices
EMThriftServer::stop"
I tried: [%{WORD}: %{NUMBER:dts}] %{GREEDYDATA:rest}\n\s+%{GREEDYDATA:ini_mess}
Upvotes: 0
Views: 16