I successfully parsed out some fields, and am trying to aggregate some of them into one fields. Anyone suggestions on how to to that would be really appreciated. I haven't found a way to do so, but I assume this must be supported as nested JSON are commonly handled by elasticsearch. Thanks
Yes, but the stock filters don't have the kind of wildcard functionality that you'd need for that. You'll have to write a small snippet of Ruby and put it in a ruby filter.
Daniele, I would start with watching the webinar and the "Get Started" section on the documentaiton page, it's what got me started! And If you run into questions, try googling first, I found more than half my answers from google around logstash, and you can always come back here if you don't find them on Google. I'm no expert like Magnus, but you can message me, and I'll do what I can to help. Good luck!
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.