Hello,my name is Pablo, this is my first post so I ask for a bit a patience about me.. im new in elk.
I'm working with netflow.
I have many fields that Im not interested to store, so I can have less data on my elk.
Im trying to remove some field with mutate (is the only way that I found).
my code is this..
remove => ["netflow.xlate_dst_port"]
I've tested many combinations but it seems that the field is not correctly defined by me.
So logstash stop processing the logs.
Only if I comment this it keep working.
Can someone tell me the correct syntax to do this works?
Thanks a lot to everybody.