Aggregate logs when fields are common in events


How can I aggregate events in logstash whenever let say the sourceAddress, username and sitename fields are equal in events and be aggregated in one event

for example the events below: - James - - James - - Katy - - James -

(system) #2

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.