I am trying to install ELK stack 7.3.2, I (filebeat included) have used the the following logstash conf., the fieldname logappname is not found in the kibana. Am I missing something?
input {
beats {
port => "5044"
}
}
The filter part of this file is commented out to indicate that it is
optional.
filter {
grok {
match => { "message" => "%{TIMESTAMP_ISO8601:logtimestamp} [%{WORD:thread}] %{LOGLEVEL:loglevel} %{GREEDYDATA:logmessage}"}
}
grok {
match => { "path" => "%{GREEDYDATA:logappname}"}
}
date {
match => ["logtimestamp", "ISO8601"]
target => "@timestamp"
}
mutate {
remove_field => ["logtimestamp"]
}
}
output {
#stdout { codec => rubydebug }
elasticsearch { hosts => [ "localhost:9200" ]}
}