I want to add ( sépartor in csv file before analysing it.
Example befor e:
2017/01/08-18:32:08mydomain.fr;151;ACC_EFFETMETEO_20170108181410.tar.gz;/arc/dacc/staging/max/SCORE;1
Result wanted:
2017/01/08-18:32:08;mydomain.fr;151;ACC_EFFETMETEO_20170108181410.tar.gz;/user/arc/staging/max/SCORE;1
Why not instead run a grok filter to capture the timestamp and put the rest of the log line into a separate variable and then apply the csv filter to this field?
You can run processing filters in any order you want. It is not uncommon to parse part of the message using one filter and then apply another to some of the fields.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.