I'm a newbie so sorry if my question is silly. I've just started out with a ELK stack which works great (6.1) and using filebeat to ship logs. My question is, I want to filter out the "message" part of the log sent but i'm getting a little confused about how to do it.
I've been reading through about grok patterns which is fine but the custom log file in question for the "message" field is several lines long and i want to filter this so i can search via it (or perhaps grep the small important info from the message?). I've tried some of the debugger sites but no luck on what i need to do.
If someone can point me in the right direction that would be great.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.