I am using filebeat 1.2.0 to fetch my log files. I have a pair of log files,
response log files.
In my logstash configuration I am doing some
aggregation between request and response files. In my log directory first request files will be falling first and after few
millisec response files get fallen into the path. So first I want to read the request file then I want to read response file second. I want to continue this process for all newly falling log files in the directory.
To do that I have utilized
ignore_older property in my filebeat config file. Will that work satisfy my scenario?
- paths: - /path/*_request.xml document_type: req close_older: 5m multiline: pattern: '<\/.*:Error>' negate: true match: before - paths: - /path/*_response.xml document_type: resp ignore_older: 15s close_older: 5m multiline: pattern: '<\/.*:Error>' negate: true match: before
Is above scenario is possible in filebeat?