Elasticsearch中几类日志记录请问解析该怎么写呀?[阿里云检索分析服务 Elasticsearch版]

Elasticsearch中几类日志记录 06-NOV-2022 14:37:30 * (CONNECT_DATA=(SID=orcl)(SERVER=DEDICATED)(CID=(PROGRAM=oracle@gddb01)(HOST=gddb01)(USER=oracle))) * (ADDRESS=(PROTOCOL=tcp)(HOST=192.168.188.171)(PORT=33254)) * establish * orcl * 0 06-NOV-2022 14:37:52 * (CONNECT_DATA=(SERVICE_NAME=orcl)(CID=(PROGRAM=D:\vmagent\gdxig\vmAgent.exe)(HOST=WIN-48NL9DQ0IFT)(USER=SYSTEM))) * (ADDRESS=(PROTOCOL=tcp)(HOST=192.168.200.37)(PORT=57698)) * establish * orcl * 0 06-NOV-2022 14:42:49 * (CONNECT_DATA=(SERVER=DEDICATED)(SERVICE_NAME=orcl)(CID=(PROGRAM=oracle@gdxig01)(HOST=gdxig01)(USER=oracle))) * (ADDRESS=(PROTOCOL=tcp)(HOST=192.168.200.176)(PORT=29530)) * establish * orcl * 0 06-NOV-2022 14:47:06 * (CONNECT_DATA=(CID=(PROGRAM=)(HOST=jdbc)(USER=))(SERVICE_NAME=yyds)(CID=(PROGRAM=)(HOST=jdbc)(USER=))) * (ADDRESS=(PROTOCOL=tcp)(HOST=192.168.200.184)(PORT=52455)) * establish * yyds * 0 大概特点是用 * 隔开的,我用下面的无法解析 %{DATESTAMP:time0} * %{DATA:data1} * %{DATA:address2} * %{DATA:action3} * %{DATA:service_name4} * %{DATA:result5} 请问解析该怎么写呀?

「点点赞赏,手留余香」

    还没有人赞赏,快来当第一个赞赏的人吧!
=====这是一个广告位,招租中,联系qq 78315851====