How to troubleshoot _grokparsefailure ?? #445
Replies: 1 comment
-
Take the original log message form discoverer (Kibana). Then, insert that log message within the Grok Debugger (Under Dev Tools). Next, take the pfelk.grok pattern file and insert that with the Grok Debugger. Finally, submit your improvements to this repo and share with others. Note: You'll want to take the filter_message vs the entire message. Reference: |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I'm using OPNsense 22.4 with pfELK 22.04 and having the unbound messages tagged with _grokparsefailure
How can I troubleshoot this parsing errors?
Looking at logstash-plain.log there are no related infos to unbound
Beta Was this translation helpful? Give feedback.
All reactions