Comments (9)
Hi, sorry for the late reply. Yes, this is possible with the gsub
function. Example:
Logfile:
INFO: request to path /abc/def/ghi/number/123123/jkl/mno
INFO: request to path /abc/def/ghi/number/123124/jkl/mno
INFO: request to path /abc/def/ghi/number/987654/jkl/mno
INFO: request to path /abc/def/ghi/number/654763/jkl/mno
config
global:
config_version: 2
input:
type: file
path: ./logfile.log
readall: true
grok:
patterns_dir: ../logstash-patterns-core/patterns
metrics:
- type: counter
name: requests_total
help: Total number of requests, partitioned by path.
match: '.* %{URIPATH:path}'
labels:
path: '{{gsub .path "(.*)/[0-9]*/(.*)" "\\1/{id}/\\2" }}'
host: localhost
port: 9144
explanation:
gsub input pattern replacement
searches for the pattern
in input
and replaces it with replacement
. In the example, it searches for "(.*)/[0-9]*/(.*)"
which is a pattern with two capture groups: (.*)
is the first capture group, capturing everything befor the id, and (.*)
is the second capture group, capturing everything after the id. The replacement "\\1/{id}/\\2"
references the first capture group \\1
and the second capture group \\2
but the id is replaced with the fixed string {id}
.
result
requests_total{path="/abc/def/ghi/number/{id}/jkl/mno"} 4
See gsub in CONFIG.md.
from grok_exporter.
Hey,
Many thanks for the reply.
This looks great, I am going to try this over the weekend.
Will update this thread post that.
Cheers,
V
from grok_exporter.
Is it possible to perform multiple gsub substitutions on the same metric label? How do I refer to the output of gsub 1 within gsub 2? In this example I want to replace both a UUID and a serial number on the same log line, but only the final gsub output is retained.
labels:
request: '{{gsub .request "(\\/)(?i)(prefix)(\\w+)(\\/?)" "\\1\\2_SERIAL\\4"}}'
request: '{{gsub .request "(?i)[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}" "UUID"}}'
from grok_exporter.
@fstab : Thank you for the inputs in the previous comment, I just got around testing this.
I have updated to the latest release 0.27 and have implemented this.
I will update the thread with all the results before closing the same.
Thank You.
from grok_exporter.
@kfreem02 I added support for this. If you build grok_exporter
from source it should work now, otherwise you need to wait for the next release. Example:
Input: message = Sender verify failed
labels:
error_message: '{{gsub (gsub .message "e" "a") "r" "x"}}'
Resulting error_message
label: "Sandax vaxify failad"
In the example, first all e
's are replaced with a
's, then all r
's replaced with x
's.
See https://github.com/fstab/grok_exporter/blob/master/template/gsub_test.go#L39-L55
from grok_exporter.
@fstab : This works great, thank you!!! Is the multiple substitution feature limited to two subs, or does it support more than two substitutions as well??
from grok_exporter.
I confirm support of nested gsub when built from source. Thanks for the fast response!
from grok_exporter.
@varundmishra it should work for any number of substitutions. If it doesn't please open a new issue.
from grok_exporter.
Great, Many Thanks @fstab.
from grok_exporter.
Related Issues (20)
- Feature Request: Option to specify ciphers or minimum TLS version HOT 2
- fail_on_missing_logfile for missing directories HOT 3
- Feature Request : Config option to expose metrics as a .prom file
- Issue reading Multiple files:
- how to match regex upper case/lower case insensitively
- Is grok able to watch only the latest log in dir?
- how to use regex group match and use matched group name label? HOT 1
- Can the latest version cover multi-line pattern match?
- if string exists HOT 7
- Use Gauge metric to find DB connectivity status HOT 1
- Exclude char HOT 2
- Does it support Elastic Search Open Distro HOT 1
- Configure for AWS ALB/CLB Logs or Cloudfront
- grok timestamp diffrent
- grok fails on insufficient permissions when fail_on_missing_logfile is false
- mutiple depth doc support HOT 1
- How can I use FuncMap to help transform data from the log, inside a template?
- Always report counter metric (initialize to zero) HOT 1
- match fails after encountering binary text within file
- Update or let someone else maintain this repo HOT 2
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from grok_exporter.