logstash-plugins / logstash-patterns-core

Apache License 2.0
2.17k stars 980 forks source link

(legacy) EXIM base-line for ECS-ification #283

Closed kares closed 3 years ago

kares commented 4 years ago

another day another grok pattern story: this time the exim (mail server) patterns seem incomplete. there seems to be partial sub-patterns and experiments with excluding specific messages which are hard to follow.

in their current (partial) form it's pretty much impossible to even come up with meaningful tests (for ECS). the proposal here tries to establish a useful (but still minimal) EXIM line - for matching "mail arrival" logs (<=).

hoping to build exim ECS support on top of this.

NOTES:

HINT: targeting ecs-wip branch, these would only get released once the ECS work is complete

kares commented 4 years ago

@yaauie anything against these to have somehow meaningful EXIM mail arrival matching to start with? otherwise ECS-ification makes little sense.