i have a logstash configuration to parse my current logs but i would like to create a sub field from my message field and that data should be parsed as a fieldname, please suggest how that is possible:
For example in the following logs how can i make a separate field for PosErr_Advancing
Hi @Badger thanks and i used the dissect and kv for this but at some places in log files because of a space timestamp is read into the next field, i will add my config and log files below, please check and suggest how i can read spaces if it appears sometimes:
sometime there is log data where i have some space within timestamp and at that time date is being read in the theatre field instead of timestamp, please check and share your views on this
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.