Hello
Newbie here, can someone help me out please?
2 log servers producing:
connection logs (user ip etc) (generated every 10 mins)
http logs (user actions) (generated on the fly)
the connection logs have username and ip (sent via filebeat to logstash)
the http logs are missing the username (sent via syslog, then loaded from syslog file to logstash)
(i cannot change this, i dont think)
how is best to fuse these two? can i add something in the logstash, or is there something I can do to merge the logs in a search in kibana?
oooh interesting. I will look, i think i might have an issue with the timing sequence of the logs... they at the moment dont arrive together. I could look into that, its a manual script that is run to produce a list of customer's current IP addresses.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.