Skip to content

Instantly share code, notes, and snippets.

@lefthand
Last active August 29, 2015 14:15
Show Gist options
  • Save lefthand/a28ebebc5d31e4b8992c to your computer and use it in GitHub Desktop.
Save lefthand/a28ebebc5d31e4b8992c to your computer and use it in GitHub Desktop.
Logstash Grok pattern for matchin the query type and primary table from a SQL query.
QUERY %{WORD:query_type}(?:\\n)?%{SPACE}(?:(?:[\a-zA-Z()'0-9-_\*+,. ]+?)?(?:\\n)?%{SPACE}(?:FROM|INTO|TEMPORARY TABLE)(?:\\n)?%{SPACE})?(?:%{WORD}\.)?%{WORD:table}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment