AM
# 2017-01-03 02:51:38 - User: Dynamic Framework. Operation performed: Monitor 'Locks on vertica' updated in 'Vertica on hp-obr-vert-1'.
match => { "message" => "(?m)^(?<date>%{YEAR}-%{MONTHNUM}-%{MONTHDAY} %{HOUR}:%{MINUTE}:%{SECOND}) - User: %{DATA:user}\. Operation performed: %{GREEDYDATA:operation}" }
remove_field => [ "message" ]
}
date {
match => [ "date", "YYYY-MM-dd HH:mm:ss" ]
}
