filter_parser uses built-in parser plugins and your own customized parser plugin, so you can reuse the predefined formats like apache2, json, etc. See Parser Plugin Overview for more details
With this example, if you receive this event:
time:
injected time (depends on your input)
record:
{"log":"192.168.0.1 - - [05/Feb/2018:12:00:00 +0900] \"GET / HTTP/1.1\" 200 777"}
Keeps the original event time in the parsed result.
With above configuration, here is the result:
Above incoming event is parsed as:
The value of time field (1622473200) is reserved as event time (2021-06-01 00:00:00.000000000 +0900).
Without reserve_time, the result is:
Above incoming event is parsed as:
The value of parsed timestamp is set as event time. The value of time field is discarded.
reserve_data
type
default
version
bool
false
0.14.9
Keeps the original key-value pair in the parsed result.
With above configuration, here is the result:
Without reserve_data, the result is:
remove_key_name_field
type
default
version
bool
false
1.2.2
Removes key_name field when parsing is succeeded.
With above configuration, here is the result:
replace_invalid_sequence
type
default
version
bool
false
0.14.9
If true, invalid string is replaced with safe characters and re-parse it.
inject_key_prefix
type
default
version
string
false
0.14.9
Stores the parsed values with the specified key name prefix.
With above configuration, here is the result:
hash_value_field
type
default
version
string
false
0.14.9
Stores the parsed values as a hash value in a field.
With above configuration, result is below:
emit_invalid_record_to_error
type
default
version
bool
true
0.14.0
Emits invalid record to @ERROR label. Invalid cases are:
key does not exist
the format is not matched
an unexpected error
You can rescue unexpected format logs in the @ERROR label.
If you want to ignore these errors, set false.
FAQ
suppress_parse_error_log is missing. What are the alternatives?
Since v1, parser filter does not support suppress_parse_error_log parameter because parser filter uses the @ERROR feature instead of internal logging to rescue invalid records. If you want to simply ignore invalid records, set emit_invalid_record_to_error false.