For further analysis I need only _grokparsefailure events in a separate file.
I thought instead of "drop" I could use "file" (like in the output section) but it doesnt work.
How can I do that or where can I find more information and explanationd about options for "_grokparsefailure"?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.