1apiVersion: fluentbit.fluent.io/v1alpha2 2kind: ClusterParser 3metadata: 4 name: samhain 5 labels: 6 fluentbit.fluent.io/enabled: "true" 7spec: 8 regex: 9 regex: ^(?<severity>DEBUG|INFO|NOTICE|WARN|MARK|ERROR|CRIT|ALERT)\s*:\s*\[(?<date>\d{4}-\d{2}-\d{2})T(?<time>\d{2}:\d{2}:\d{2}\+\d{4})\]\s*msg=<(?!EXIT|START)(?<message>.*?)>(?>,\s*)?(?<attributes>.*)$