I've appended a unique id to the very end of every log line that tags a log message as being part of a single http request. Generally an http request has 5 log lines in my application and if there are multiple users, the lines are not necessarily in order. Here's a contrived example
1 INFO 126.96.36.199 GET /search? params='foo' unique_id=12345ABCDE
2 INFO 188.8.131.52 POST /submit? params='bar' unique_id=ZZZZ8888
3 INFO 184.108.40.206 Completed 200 34ms unique_id=12345ABCDE
My goal is to combine lines 1 and 3 into the same elasticsearch document by matching on the unique_id. Is there a good solution for this with logstash? Thanks!