Is there a method to rename the fields extracted via the kv plugin by adding a prefex (example ctf): SENTINEL_STATE by ctf.SENTINEL_STATE?
Best regards,
make sure you are passing only part of string to kv filter
as:
IDTU=A0007GK PART=LKOR STATE=Y PHASE=Y PHASESTEP=C DIRECT=S TYPE=F SENTINEL_STATE=POST_PROC
Use dissect or grok parsing to separate the string for kv filter
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.