Elasticsearch index


(sanjeebkdeka) #1

Is it possible to create index on the content of a message?
If so how?

--
You received this message because you are subscribed to the Google Groups "elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email to elasticsearch+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/elasticsearch/d633b0b6-661f-4344-a9de-c5044e5c7b59%40googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.


(David Pilato) #2

Could you clarify what you are looking for?

What is a message?

--
David Pilato | Technical Advocate | Elasticsearch.com
@dadoonet | @elasticsearchfr

Le 5 février 2014 at 10:55:03, sanjeebkdeka@gmail.com (sanjeebkdeka@gmail.com) a écrit:

Is it possible to create index on the content of a message?
If so how?

You received this message because you are subscribed to the Google Groups "elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email to elasticsearch+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/elasticsearch/d633b0b6-661f-4344-a9de-c5044e5c7b59%40googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.

--
You received this message because you are subscribed to the Google Groups "elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email to elasticsearch+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/elasticsearch/etPan.52f20c04.836c40e.d955%40MacBook-Air-de-David.local.
For more options, visit https://groups.google.com/groups/opt_out.


(sanjeebkdeka) #3

Example complete log is: <10> Jan 17, 2014 TestHost This test message is
from src=IP1 to dest=IP2.

The message part here is : This test message from src=IP1 to dest=IP2

The requirement is to index based on the meta( such as src and dest ) in
the message.

On Wednesday, February 5, 2014 3:25:00 PM UTC+5:30, sanjee...@gmail.com
wrote:

Is it possible to create index on the content of a message?
If so how?

--
You received this message because you are subscribed to the Google Groups "elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email to elasticsearch+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/elasticsearch/e1d4d159-ec5d-405d-b598-cfb7b0190823%40googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.


(David Pilato) #4

Not sure I fully understand but I guess you should look at logstash: http://www.elasticsearch.org/overview/logstash/

I think that with logstash you could extract from your line content you need, build a JSON and push it to elasticsearch.

--
David Pilato | Technical Advocate | Elasticsearch.com
@dadoonet | @elasticsearchfr

Le 5 février 2014 at 11:36:55, sanjeebkdeka@gmail.com (sanjeebkdeka@gmail.com) a écrit:

Example complete log is: <10> Jan 17, 2014 TestHost This test message is from src=IP1 to dest=IP2.

The message part here is : This test message from src=IP1 to dest=IP2

The requirement is to index based on the meta( such as src and dest ) in the message.

On Wednesday, February 5, 2014 3:25:00 PM UTC+5:30, sanjee...@gmail.com wrote:
Is it possible to create index on the content of a message?
If so how?

You received this message because you are subscribed to the Google Groups "elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email to elasticsearch+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/elasticsearch/e1d4d159-ec5d-405d-b598-cfb7b0190823%40googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.

--
You received this message because you are subscribed to the Google Groups "elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email to elasticsearch+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/elasticsearch/etPan.52f216a7.6ceaf087.d955%40MacBook-Air-de-David.local.
For more options, visit https://groups.google.com/groups/opt_out.


(Mark Walkom) #5

Yep, this is spot on. Logstash + ES will do this.

Regards,
Mark Walkom

Infrastructure Engineer
Campaign Monitor
email: markw@campaignmonitor.com
web: www.campaignmonitor.com

On 5 February 2014 21:47, David Pilato david@pilato.fr wrote:

Not sure I fully understand but I guess you should look at logstash:
http://www.elasticsearch.org/overview/logstash/

I think that with logstash you could extract from your line content you
need, build a JSON and push it to elasticsearch.

--
David Pilato | Technical Advocate | Elasticsearch.com
@dadoonet https://twitter.com/dadoonet | @elasticsearchfrhttps://twitter.com/elasticsearchfr

Le 5 février 2014 at 11:36:55, sanjeebkdeka@gmail.com (
sanjeebkdeka@gmail.com) a écrit:

Example complete log is: <10> Jan 17, 2014 TestHost This test message is
from src=IP1 to dest=IP2.

The message part here is : This test message from src=IP1 to dest=IP2

The requirement is to index based on the meta( such as src and dest ) in
the message.

On Wednesday, February 5, 2014 3:25:00 PM UTC+5:30, sanjee...@gmail.comwrote:

Is it possible to create index on the content of a message?
If so how?

--
You received this message because you are subscribed to the Google Groups
"elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an
email to elasticsearch+unsubscribe@googlegroups.com.
To view this discussion on the web visit
https://groups.google.com/d/msgid/elasticsearch/e1d4d159-ec5d-405d-b598-cfb7b0190823%40googlegroups.com
.
For more options, visit https://groups.google.com/groups/opt_out.

--
You received this message because you are subscribed to the Google Groups
"elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an
email to elasticsearch+unsubscribe@googlegroups.com.
To view this discussion on the web visit
https://groups.google.com/d/msgid/elasticsearch/etPan.52f216a7.6ceaf087.d955%40MacBook-Air-de-David.local
.

For more options, visit https://groups.google.com/groups/opt_out.

--
You received this message because you are subscribed to the Google Groups "elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email to elasticsearch+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/elasticsearch/CAEM624bDiLVSbic2-jhERQKGAMt1xBS2zE%3D-5KAvajOqY6vRXQ%40mail.gmail.com.
For more options, visit https://groups.google.com/groups/opt_out.


(system) #6