Event enrichment using logstash



are there any plugins I can use to enrich my log entries , eg , querying other sources or files to get more data and create fields based on that ?


(Christian Dahlqvist) #2

Yes, there are quite a few. Have a look at the list of filter plugins. Which ones that are suitable depends on what you want to do, but general ones are jdbc_static, jdbc_streaming and translate.

(system) #3

