Based on other posts I've made, I've learned that I should be able dissect a field (in this case, it's eventData.ObjectName into sub-fields, however I'm having an issue where some messages don't have the full length of my dissect, and therefore throw a _dissectfailure
What I'm seeing is that the messages in the example: 2, 3, and 5 will parse fine, but 1 and 4 will throw the failure. Note, this won't break, but I'm dealing with ~100,000 messages per minute, so I need this to be efficient, accurate, and now throw failures. Thanks in advance.
Hope you don't mind if I mention you @Badger since you're extremely helpful. I owe you a beer (or something else if you don't drink).
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.