로그 한 줄을 필드로 쪼갤 때 쓰는 grok 패턴과, 쪼갠 결과를 담을 Avro 스키마를 짝으로 둔다. Logstash · Fluentd · NiFi(GrokReader)에서 그대로 쓸 수 있다.
%{TIMESTAMP_ISO8601:timestamp} %{LOGLEVEL:log_level} \[%{DATA:log_type}\] %{GREEDYDATA:log_message}
{
"type": "record",
"name": "LogRecord",
"namespace": "com.example.nifi",
"fields": [
{ "name": "timestamp", "type": "string" },
{ "name": "log_level", "type": "string" },
{ "name": "log_type", "type": "string" },
{ "name": "log_message", "type": "string" }
]
}
%{SYSLOGTIMESTAMP:timestamp} %{HOSTNAME:hostname} %{DATA:program}(?:\[%{POSINT:pid}\])?: %{GREEDYDATA:message}
{
"type": "record",
"name": "SyslogRecord",
"namespace": "com.example.syslog",
"fields": [
{ "name": "timestamp", "type": ["null", "string"], "default": null },
{ "name": "hostname", "type": ["null", "string"], "default": null },
{ "name": "program", "type": ["null", "string"], "default": null },
{ "name": "pid", "type": ["null", "string"], "default": null },
{ "name": "message", "type": ["null", "string"], "default": null }
]
}