Skip to content

Conversation

@wyardley
Copy link

@wyardley wyardley commented Apr 7, 2016

See #141

This log fails to parse for me with the COMMONAPACHELOG / COMBINEDAPACHELOG grok rules:

10.0.0.1 - [email protected] [07/Apr/2016:18:42:24 +0000] "GET /bar/foo/users/1/username%40example.com/authenticate?token=blargh&client_id=15 HTTP/1.1" 400 75 "" "Mozilla/5.0 (iPad; CPU OS 9_3_1 like Mac OS X) AppleWebKit/601.1.46 (KHTML, like Gecko) Version/9.0 Mobile/13E238 Safari/601.1"

@elasticsearch-release
Copy link

Jenkins standing by to test this. If you aren't a maintainer, you can ignore this comment. Someone with commit access, please review this and clear it for Jenkins to run; then say 'jenkins, test it'.

@wyardley
Copy link
Author

wyardley commented Apr 7, 2016

@karmi Signed CLA.

@wyardley
Copy link
Author

wyardley commented Apr 7, 2016

FWIW, I was able to generate an Apache 2.4 log entry with an email address in the username field as well
10.0.0.1 - [email protected] [07/Apr/2016:12:49:36 -0700] "GET /authtest/ HTTP/1.1" 200 679

@wyardley
Copy link
Author

wyardley commented Apr 8, 2016

I am not setup to develop on Logstash, so might be some minor issues (wasn't able to test), but added a basic test for this as well.

@andrewvc andrewvc added the P2 label May 17, 2016
@elasticsearch-bot
Copy link

João Duarte merged this into the following branches!

Branch Commits
master c0e48b6, 17915d6

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants