Different input source with same information problem

(shao-yu,wang) #1

I want to use one filter to fetch same information from multiple input logfile like:
userA's log: "git clone" and userB's log: "git clone"
can I gork this and make difference output information to elasticsearch like:

(Magnus Bäck) #2

I don't understand the question. Instead of describing the problem give concrete examples. What do the log files look like? What does the resulting event produced by Logstash look like? Use JSON notation.

(system) #3

