I have a python microservice that output logs like so:
INFO ; 2022-12-02 01:30:00; bla bla bla...
DEBUG ; 2022-12-02 01:30:00; bla bla bla...
Note how the space is different on the loglevel. I am parsing it like so:
- dissect:
tokenizer: "%{log.level} ;%{+timestamp} ; %{?message}"
field: "message"
target_prefix: ""
Which work for the first line, not the second. Anyone know if there is a solution for such case?
Thank you.
1条答案
按热度按时间nle07wnf1#
您需要使用右填充修饰符