I really need some help parsing the below log and matching with grok
Mar 19 17:23:12:00 Alert - Traffic Gap Detected - severity[Alert] source[Text1/Text2] reason[MajorSet] count[1] value[1]
I want similar to this:
timesamp:Mar 19 17:23:12:00
Alert: Alert - Traffic Gap Detected -
severity: Alert
source:Text1/Text2
reason:MajorSet
count:1
value:1
grok{
match => [ "message" => "%{SYSLOGTIMESTAMP:timestamp} %{GREEDYDATA: Alert - Traffic Gap Detected} %{WORD:severity]"]
}
Thanks for any help!