Exported fields in filebeat processors

(John) #1


Documentation about filebeat's processors

references fields like http.response.code, etc:

equals: http.response.code: 200

But in "Exported fields" section:

I see only general fields like type, message, offset, etc., nothing log-line-content-specific.

Is there any way to parse log line against regexp to extract some data to be used in expressions? Or how do these examples correlate with real life?


Ingest pipeline: how to ignore log line based on condition
(Tudor Golubenco) #2

The examples are the same for all beats, and that particular example is from Packetbeat, which has that field. Sorry for the confusion. If you need to parse logs, I recommend using either Logstash or the Elasticsearch Ingest Node.

(system) #3

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.