<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: ExtractGrok processor - Writing Regex to parse Cisco syslog in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/ExtractGrok-processor-Writing-Regex-to-parse-Cisco-syslog/m-p/233098#M75243</link>
    <description>&lt;P&gt;I got the pattern file created and used in Nifi.&lt;/P&gt;&lt;P&gt;I am using this in grok expression:&lt;/P&gt;&lt;P&gt;&amp;lt;(?&amp;lt;priority&amp;gt;[0-9]+)&amp;gt;(?&amp;lt;sequence&amp;gt;[0-9]+): *(\*)?%{CISCOTIMESTAMP}: (?&amp;lt;host&amp;gt;[a-zA-Z0-9_]+): %(?&amp;lt;facility&amp;gt;[A-Z0-9_]+)-(?&amp;lt;severity&amp;gt;[0-7]+)-(?&amp;lt;mnemonic&amp;gt;[A-Z0-9_]+): (?&amp;lt;message&amp;gt;.+)&lt;/P&gt;&lt;P&gt;grok pattern file - &lt;A href="https://github.com/apache/nifi/blob/master/nifi-nar-bundles/nifi-standard-bundle/nifi-standard-processors/src/test/resources/TestExtractGrok/patterns"&gt;https://github.com/apache/nifi/blob/master/nifi-nar-bundles/nifi-standard-bundle/nifi-standard-processors/src/test/resources/TestExtractGrok/patterns&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/apache/nifi/blob/master/nifi-nar-bundles/nifi-standard-bundle/nifi-standard-processors/src/test/resources/TestExtractGrok/patterns"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This expression works fine on Grok debugger site - &lt;A href="http://grokdebug.herokuapp.com/" target="_blank"&gt;http://grokdebug.herokuapp.com/&lt;/A&gt;. But not on Nifi. What am i doing wrong?&lt;/P&gt;&lt;P&gt;Sample cisco router log data i am using:&lt;/P&gt;&lt;P&gt;&amp;lt;189&amp;gt;22: *Apr 29 13:58:40.411: user: %SYS-5-CONFIG_I: Configured from console by console&lt;/P&gt;</description>
    <pubDate>Wed, 07 Mar 2018 02:14:51 GMT</pubDate>
    <dc:creator>jayanthimala_ja</dc:creator>
    <dc:date>2018-03-07T02:14:51Z</dc:date>
    <item>
      <title>ExtractGrok processor - Writing Regex to parse Cisco syslog</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/ExtractGrok-processor-Writing-Regex-to-parse-Cisco-syslog/m-p/233095#M75240</link>
      <description>&lt;P&gt;I am running the Nifi on Docker. Nifi ParseSyslog fails for Cisco syslog, so trying to write custom regex parsing using Extract Grok processor.&lt;/P&gt;&lt;P&gt;What is the Grok pattern file to be provided? I provided Grok expression, but it still looks for Grok pattern file. &lt;/P&gt;&lt;P&gt;Any pointers on this will help. Thanks!&lt;/P&gt;</description>
      <pubDate>Sat, 03 Mar 2018 06:18:39 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/ExtractGrok-processor-Writing-Regex-to-parse-Cisco-syslog/m-p/233095#M75240</guid>
      <dc:creator>jayanthimala_ja</dc:creator>
      <dc:date>2018-03-03T06:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: ExtractGrok processor - Writing Regex to parse Cisco syslog</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/ExtractGrok-processor-Writing-Regex-to-parse-Cisco-syslog/m-p/233096#M75241</link>
      <description>&lt;P&gt;Hi Jay,&lt;/P&gt;&lt;P&gt;You need to provide a file such as &lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/apache/nifi/blob/master/nifi-nar-bundles/nifi-standard-bundle/nifi-standard-processors/src/test/resources/TestExtractGrok/patterns" target="_blank"&gt;https://github.com/apache/nifi/blob/master/nifi-nar-bundles/nifi-standard-bundle/nifi-standard-processors/src/test/resources/TestExtractGrok/patterns&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You could also use the ConvertRecord processor with a GrokReader. In this case there is already a default pattern file pre-loaded with the reader.&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Pierre&lt;/P&gt;</description>
      <pubDate>Sat, 03 Mar 2018 18:16:02 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/ExtractGrok-processor-Writing-Regex-to-parse-Cisco-syslog/m-p/233096#M75241</guid>
      <dc:creator>pvillard</dc:creator>
      <dc:date>2018-03-03T18:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: ExtractGrok processor - Writing Regex to parse Cisco syslog</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/ExtractGrok-processor-Writing-Regex-to-parse-Cisco-syslog/m-p/233097#M75242</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/5078/pvillard.html" nodeid="5078"&gt;@Pierre Villard&lt;/A&gt; - Thanks for the reply. I looked at this pattern file. But I am not sure how to link this file to Grok pattern file on nifi.&lt;/P&gt;&lt;P&gt;I am running it on docker compose, so how do i store this pattern file and what path to provide in the Nifi?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 00:24:36 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/ExtractGrok-processor-Writing-Regex-to-parse-Cisco-syslog/m-p/233097#M75242</guid>
      <dc:creator>jayanthimala_ja</dc:creator>
      <dc:date>2018-03-06T00:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: ExtractGrok processor - Writing Regex to parse Cisco syslog</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/ExtractGrok-processor-Writing-Regex-to-parse-Cisco-syslog/m-p/233098#M75243</link>
      <description>&lt;P&gt;I got the pattern file created and used in Nifi.&lt;/P&gt;&lt;P&gt;I am using this in grok expression:&lt;/P&gt;&lt;P&gt;&amp;lt;(?&amp;lt;priority&amp;gt;[0-9]+)&amp;gt;(?&amp;lt;sequence&amp;gt;[0-9]+): *(\*)?%{CISCOTIMESTAMP}: (?&amp;lt;host&amp;gt;[a-zA-Z0-9_]+): %(?&amp;lt;facility&amp;gt;[A-Z0-9_]+)-(?&amp;lt;severity&amp;gt;[0-7]+)-(?&amp;lt;mnemonic&amp;gt;[A-Z0-9_]+): (?&amp;lt;message&amp;gt;.+)&lt;/P&gt;&lt;P&gt;grok pattern file - &lt;A href="https://github.com/apache/nifi/blob/master/nifi-nar-bundles/nifi-standard-bundle/nifi-standard-processors/src/test/resources/TestExtractGrok/patterns"&gt;https://github.com/apache/nifi/blob/master/nifi-nar-bundles/nifi-standard-bundle/nifi-standard-processors/src/test/resources/TestExtractGrok/patterns&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/apache/nifi/blob/master/nifi-nar-bundles/nifi-standard-bundle/nifi-standard-processors/src/test/resources/TestExtractGrok/patterns"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This expression works fine on Grok debugger site - &lt;A href="http://grokdebug.herokuapp.com/" target="_blank"&gt;http://grokdebug.herokuapp.com/&lt;/A&gt;. But not on Nifi. What am i doing wrong?&lt;/P&gt;&lt;P&gt;Sample cisco router log data i am using:&lt;/P&gt;&lt;P&gt;&amp;lt;189&amp;gt;22: *Apr 29 13:58:40.411: user: %SYS-5-CONFIG_I: Configured from console by console&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 02:14:51 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/ExtractGrok-processor-Writing-Regex-to-parse-Cisco-syslog/m-p/233098#M75243</guid>
      <dc:creator>jayanthimala_ja</dc:creator>
      <dc:date>2018-03-07T02:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: ExtractGrok processor - Writing Regex to parse Cisco syslog</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/ExtractGrok-processor-Writing-Regex-to-parse-Cisco-syslog/m-p/233099#M75244</link>
      <description>&lt;P&gt;I got it working. I had to add the custom naming fields used in the Grok expression into the pattern file.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 03:19:27 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/ExtractGrok-processor-Writing-Regex-to-parse-Cisco-syslog/m-p/233099#M75244</guid>
      <dc:creator>jayanthimala_ja</dc:creator>
      <dc:date>2018-03-07T03:19:27Z</dc:date>
    </item>
    <item>
      <title>Re: ExtractGrok processor - Writing Regex to parse Cisco syslog</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/ExtractGrok-processor-Writing-Regex-to-parse-Cisco-syslog/m-p/289918#M75245</link>
      <description>&lt;P&gt;Hi, can you explain how did you solve this problem?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2020 11:18:43 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/ExtractGrok-processor-Writing-Regex-to-parse-Cisco-syslog/m-p/289918#M75245</guid>
      <dc:creator>mabr</dc:creator>
      <dc:date>2020-02-17T11:18:43Z</dc:date>
    </item>
  </channel>
</rss>

