Hello,
I have problem and I don't understand that.
I send logs with filebeat to logstash, it looks like this
When I want to search something ex. a word
error
, I get something like below,
rest default fields I cut out,
below there are fields except
message
- which is default - created by me in grok
filter
In field
m19-custom [GW4665p uPGEDf70 OPOM_PWD - error #50073]
there is word error
but it is not mark. It looks like search don't work on fields created by me. On default fields search works normally.
fields created in grok filter
(%{TIMESTAMP_ISO8601:m01-date-time})?,
(%{GREEDYDATA:m06-source-context})?,
(%{NUMBER:m10-internal-id})?,
(%{GREEDYDATA:m12-id})?,
(%{NUMBER:m16-count})?,
(%{GREEDYDATA:m19-custom})?,
What and where should I do to fix search in all fields?