Re: [graylog2] converters in grok pattern

2016-06-23 Thread Андрей Грошев
четверг, 23 июня 2016 г., 12:43:21 UTC+3 пользователь Jan Doberstein написал: > > Hej, > > > > On 23. Juni 2016 at 09:22:40, Андрей Грошев (gree...@gmail.com > ) wrote: > > > And for example request http_code:<204 don't worked. > > I found example define pattern as %{INT:http_code;int} (a

Re: [graylog2] converters in grok pattern

2016-06-23 Thread Jan Doberstein
Hej, On 23. Juni 2016 at 09:22:40, Андрей Грошев (greenx...@gmail.com) wrote: > And for example request http_code:<204 don't worked. > I found example define pattern as %{INT:http_code;int} (a semicolon, not a > colon as in elastic) > And it worked, index mapped in elastic as: > > "http_code":

[graylog2] converters in grok pattern

2016-06-23 Thread Андрей Грошев
Hello people! Again stupid question:) I try processed syslog message through grok pattern. I get all the required fields. But all them have string type. And for example request http_code:<204 don't worked. I found example define pattern as %{INT:http_code;int} (a semicolon, not a colon as in