I am using ELK 6.8.0 and I want to add the beat version to the indexname I have configured in an Logstash output. I have configured it currently like this
Have you tried to Grok Match the Beat Name from the Plain Log? And simply use the fieldname in which you put the Value In the Indexname? I don't really know the format of your logs so i can't just paste random stuff in here.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.