Currently the Gitea parser ignores failed API authentication. I don't have any experience with grok patterns, but according to https://www.javainuse.com/grok this should be enough:
^%{YEAR}/%{MONTHNUM}/%{MONTHDAY} %{TIME} .*?router: completed %{WORD:method} %{URIPATH:path} for %{IP:remote_ip}:%{NUMBER:remote_port}, 401 %{WORD} in
{YEAR}/%{MONTHNUM}/%{MONTHDAY} %{TIME} could probably be replaced with {GITEA_CUSTOMDATE:timestamp}
Sample log entry:
2026/07/22 19:40:17 ...eb/routing/logger.go:102:func1() [I] router: completed POST /api/v1/repos/flex/flexcore/hooks for 11.111.111.111:0, 401 Unauthorized in 1.8ms @ shared/middleware.go:60(shared.Middlewares.apiAuthentication)
Currently the Gitea parser ignores failed API authentication. I don't have any experience with grok patterns, but according to https://www.javainuse.com/grok this should be enough:
^%{YEAR}/%{MONTHNUM}/%{MONTHDAY} %{TIME} .*?router: completed %{WORD:method} %{URIPATH:path} for %{IP:remote_ip}:%{NUMBER:remote_port}, 401 %{WORD} in{YEAR}/%{MONTHNUM}/%{MONTHDAY} %{TIME}could probably be replaced with{GITEA_CUSTOMDATE:timestamp}Sample log entry:
2026/07/22 19:40:17 ...eb/routing/logger.go:102:func1() [I] router: completed POST /api/v1/repos/flex/flexcore/hooks for 11.111.111.111:0, 401 Unauthorized in 1.8ms @ shared/middleware.go:60(shared.Middlewares.apiAuthentication)