Skip to content

Cherry-pick #10135 to 6.6: Elasticsearch/audit fileset should be more lenient in parsing node name#10465

Merged
ycombinator merged 3 commits intoelastic:6.6from
ycombinator:backport_10135_6.6
Feb 1, 2019
Merged

Cherry-pick #10135 to 6.6: Elasticsearch/audit fileset should be more lenient in parsing node name#10465
ycombinator merged 3 commits intoelastic:6.6from
ycombinator:backport_10135_6.6

Conversation

@ycombinator
Copy link
Copy Markdown
Contributor

Cherry-pick of PR #10135 to 6.6 branch. Original message:

Resolves #10035.

This PR:

  • Uses DATA instead of WORD in the grok pattern for parsing out elasticsearch.node.name,
  • Breaks out the grok pattern into pattern definitions to increase readability
  • Removes a redundant ? after a * in the grok pattern (between elasticsearch.audit.action and elasticsearch.audit.uri), and
  • Properly reindents the pipeline JSON (so you might want to view the diff with ?w=1 appended to the URL)

…me (#10135)

Resolves #10035.

This PR:

* Uses `DATA` instead of `WORD` in the grok pattern for parsing out `elasticsearch.node.name`,
* Breaks out the grok pattern into pattern definitions to increase readability
* Removes a redundant `?` after a `*` in the grok pattern (between `elasticsearch.audit.action` and `elasticsearch.audit.uri`), and
* Properly reindents the pipeline JSON (so you might want to view the diff with `?w=1` appended to the URL)

(cherry picked from commit 93851c2)
@ycombinator ycombinator merged commit 148c283 into elastic:6.6 Feb 1, 2019
@ycombinator ycombinator deleted the backport_10135_6.6 branch February 1, 2019 10:35
leweafan pushed a commit to leweafan/beats that referenced this pull request Apr 28, 2023
…be more lenient in parsing node name (elastic#10465)

Cherry-pick of PR elastic#10135 to 6.6 branch. Original message: 

Resolves elastic#10035.

This PR:

* Uses `DATA` instead of `WORD` in the grok pattern for parsing out `elasticsearch.node.name`,
* Breaks out the grok pattern into pattern definitions to increase readability
* Removes a redundant `?` after a `*` in the grok pattern (between `elasticsearch.audit.action` and `elasticsearch.audit.uri`), and
* Properly reindents the pipeline JSON (so you might want to view the diff with `?w=1` appended to the URL)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants