filter { if [program] == "yum" { grok { match => [ "message", "%{WORD:action}: %{NUMBER:order_number}:%{GREEDYDATA:application_name}" ] add_tag => "installation" } } }
filter { if [program] == "yum" { grok { match => [ "message", "%{WORD:action}: %{NUMBER:order_number}:%{GREEDYDATA:application_name}" ] add_tag => "installation" } } }