I'm not really fluent with the syntax yet. In the Logstash config, where would your suggestion go? Should I add the type and index into the csv column list. So would I change the filter{} clause, like this
You can have 2 fields, one analyzed and one not_analyzed. If you do a query you can use the analyzed field. And if you do a aggregation, you can do it on the not_analyzed field.
You need to update your index mapping in Elasticsearch.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.