Hello over there!
I'm looking for a way to combine two logs into one event. Say I have log lines that look like:
[timestamp] [unique id] [some message]
... // different format/type log messages goes here
[timestamp] [unique id] [a message]
I need to make one event instead of 2 combining first and last events if their unique ids matches. Other log lines between has to be processed their own way and it's something I can do with if statement. I wonder if aggregate + drop filters is something I actually need to use.
Thanks in advance,