fluent-plugin-grok-parser
logstash-patterns
fluent-plugin-grok-parser | logstash-patterns | |
---|---|---|
1 | 4 | |
105 | 233 | |
1.0% | 0.0% | |
2.7 | 2.1 | |
8 months ago | about 1 year ago | |
Ruby | Python | |
GNU General Public License v3.0 or later | - |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
fluent-plugin-grok-parser
-
A portable, modern regular expression language
It may have originated from a project but many other log parser projects such as Vector and fluentd have such support.
https://vector.dev/docs/reference/vrl/examples/#parse_grok
https://github.com/fluent/fluent-plugin-grok-parser
logstash-patterns
- Grok filter working in online debuggers but not in actual implementation
-
A portable, modern regular expression language
Why don't languages have grok patterns in their standard libraries?
It seems to only exist in log parsing ecosystems but this really helps with getting rid of little bugs and wrong parsing of specific regex patterns.
Instead of doing "^\d+(\.\d+){3}$" for IP checking which is clearly wrong, you'd do "%{IPV4:ip}" which is so much better.
List of known patterns : https://github.com/hpcugent/logstash-patterns/blob/master/fi...
Even for PHP a third party library only has 15 stars.
-
Dissect pattern help
in case you haven't, it can be found here. https://github.com/hpcugent/logstash-patterns/blob/master/files/grok-patterns
-
Writing an effective GROK pattern
Also, some of the patterns can be referred from https://github.com/hpcugent/logstash-patterns/blob/master/files/grok-patterns I personally prefer the above link for constructing grok pattern.
What are some alternatives?
common-regex - Most common regex
logstash-patterns-core
rx - Standalone version of Emacs' rx macro
JSVerbalExpressions - JavaScript Regular expressions made easy
kbnf - KBNF has been renamed to Dogma
hfst - Helsinki Finite-State Technology (library and application suite)
fluent-plugin-rewrite-tag-filter - Fluentd Output filter plugin to rewrite tags that matches specified attribute.
oil - Oils is our upgrade path from bash to a better language and runtime. It's also for Python and JavaScript users who avoid shell!