Grok自定义模式:匹配特定域名并赋值给domain变量
Got it, let's work through this problem. The default HOSTNAME Grok pattern doesn't handle leading wildcards like *, so we'll need a custom approach to grab that *.server.domain.com string into your domain variable.
Step 1: Define a Custom Wildcard Domain Pattern
First, create a custom pattern (we'll name it WILDCARD_DOMAIN) tailored to match domains with a leading wildcard:
WILDCARD_DOMAIN \*\.%{HOSTNAME}
This pattern specifically targets strings starting with *. followed by a standard valid hostname—perfect for your target *.server.domain.com.
Step 2: Full Grok Expression for Your Log
Combine this custom pattern with a complete Grok expression that fits your log's structure:
%{SYSLOGTIMESTAMP:timestamp} %{IP:source_ip} %{DATA:process}\[%{NUMBER:pid}\]: The CNAME record '%{WILDCARD_DOMAIN:domain}' is successfully added into BlackList RPZ zone\(s\) with comment '%{DATA:comment}' and policy '%{DATA:policy}'.
Quick breakdown of key elements:
%{SYSLOGTIMESTAMP:timestamp}: Captures the log's timestamp%{IP:source_ip}: Grabs the source IP address from the log%{DATA:process}\[%{NUMBER:pid}\]: Captures the process name and its associated PID%{WILDCARD_DOMAIN:domain}: Uses our custom pattern to pull the wildcard domain directly into thedomainfield- We escape
(s)as\(s\)because parentheses are special characters in Grok syntax
Step 3: Verify the Pattern
When you run this against your sample log, you'll get a structured output like this (JSON format for clarity):
{ "timestamp": "Apr 4 10:46:25", "source_ip": "10.42.203.245", "process": "ThreatInsightAnalytics", "pid": "29407", "domain": "*.server.domain.com", "comment": "[2018-04-04 10:46:22 UTC] [member: infoblox.localdomain] DNS Tunneling", "policy": "No Such Domain" }
内容的提问来源于stack exchange,提问作者nowy

