Thus, you can use the grok debugger application:
grok, "". , , - , , . ( JSON, , )
Grok - , . :
Input: [Thu Feb 27 13:22:44 2014] [error] [client 10.110.64.71] script not found or unable to stat: /var/www/cgi-bin/php4
Your_Pattern: \[%{HTTPDATE:timestamp}\] \[%{WORD:class}\] \[%{WORD:originator} %{IP:clientip}\] %{GREEDYDATA:errmsg}
" ". , HTTPDATE :% {MONTHDAY}/% {MONTH}/% {YEAR}:% {TIME}% {INT}, .
, , . . regex . , .
:
\[(?<timestamp>%{DAY:day} %{MONTH:month} %{MONTHDAY} %{TIME} %{YEAR})\] \[%{WORD:class}\] \[%{WORD:originator} %{IP:clientip}\] %{GREEDYDATA:errmsg}
grok% {DAY: day}% {MONTH: month}% {MONTHDAY}% {TIME}% {YEAR}
. :
(?<new_name>regular expression / grok).
post groks.