You did not share how your logs are getting in to your NiFi.
But once ingested, you could use a PartitionRecord processor using one of the following readers to handle parsing your log files: - GrokReader - SyslogReader - Syslog5424Reader
You can then use your choice of Record Writers to output your individual split log outputs. You would then add one custom property that is used to group like log entries by the log_level This custom property will become a new FlowFile attribute on the output FlowFiles.
You can then use a RouteOnAttribute processor to filter out only FlowFiles where the log_level is set to ERROR.
Here is a simple flow I created that tails NiFi's app log and partitions logs by log_level and and then routes log entries for WARN or ERROR.
I use the GrokReader with the following GrokExpression