When creating JSON structured logs using the Logstash Logback encoder(https://mvnrepository.com/artifact/net.logstash.logback/logstash-logback-encoder/4.11) has anyone had any trouble with SumoLogic parsing the log files?
I will want to be able to query the logs using JSON fields as parameters similar to in the example below.
(_source=container-logs ) AND _sourcename = RApp*
| json field=_raw "response-time" as responseTime
| json field=_raw "url" as url
| avg(responseTime) group by url
Are there any special formatting you have to do or configuration so that the logs are properly ingested and parsed?
Please sign in to leave a comment.