Hello,
I am asking as a newbie.
I have two kinds of log type. One type gives me ID's of items along with
other information. The other type gives me a particular id and its relevant
information such as its name and so on.
I want to perform a search and perform an update on the first type of log
such that the item's other information (name and so on) can be added to
that log line based on the matching Id.
As an example =>
First Type:
{
- "_index": "logstash-2014.10.19",
- "_type": "logs",
- "_id": "VRh2iqsiRMmgS87BEIuduA",
- "_version": 1,
- "_score": 1,
- "_source": {
- "@timestamp": "2014-10-19T22:12:30.470Z",
- "message": "18 Oct 2014 02:21:48,640 DEBUG [http-8080-1]
(com.rtx.db.Where:45) -
[2459BC896ECDFF92E85797F84E9DFCB4][page4][pwu2]EmptyPolicyApplicable =
false ", - "@version": "1",
- "host": "kilsedar-N55SL",
- "path": [
- "/home/kilsedar/Downloads/RTX.log",
- "com.rtx.db.Where:45"
],
- "tags": [
- "_xmlparsefailure",
- "LogData"
],
- "day": "18",
- "month": "Oct",
- "year": "2014",
- "time": "02:21:48,640",
- "mode": "DEBUG",
- "httpPort": "http-8080-1",
- "sessionId": "2459BC896ECDFF92E85797F84E9DFCB4",
- "pageId": "page4",
- "Info": "EmptyPolicyApplicable = false ",
- "pwuId": "pwu2"
}
}
Second Type:
{
- "_index": "logstash-2014.10.19",
- "_type": "logs",
- "_id": "LqDWHES9S1qS2WBYxq9fRA",
- "_version": 1,
- "_score": 1,
- "_source": {
- "@timestamp": "2014-10-19T22:12:20.322Z",
- "message": "
", - "@version": "1",
- "tags": [
- "multiline",
- "_xmlparsefailure",
- "_grokparsefailure",
- "WebModel"
],
- "host": "kilsedar-N55SL",
- "path":"/home/kilsedar/Downloads/WebModel/sv1/area10/page4.wr",
- "powerIndexUnitId": [
- "sv1#area10#page4#pwu2"
],
- "sv1#area10#page4#pwu2"
- "powerIndexUnitName": [
- "Product List"
],
- "Product List"
- "powerIndexUnitEntityId": [
- "pkg1#ent8"
]
}
- "pkg1#ent8"
}
So in this case I want to add powerIndexUnitName and powerIndexUnitEntityId
to the first Log as new fields.
Would it be possible and what kind of approach would you suggest?
Thank you!
--
You received this message because you are subscribed to the Google Groups "elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email to elasticsearch+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/elasticsearch/1aaad945-37a4-4764-97b5-49835eb9869e%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.