I use Logstash to filter data from big files like
mongos.log. It receives thousands of entries from these logs and I use grok to filter data and display it in Kibana.
There are many entries that logstash receives that I don't really care about which why is these entries are failed to be parsed by grok and are given the
_grokparsefailure. Those entries take a huge amount of data. I thought about having logstash deleting them right away but this would make debugging impossible.
Is it possible to have entries that are tagged
_grokparsefailure deleted after 1 day? Thanks ahead!