I would like to drop any messages that do not contain WRN or ERR from filebeats, but I can't figure out how to format my regular expression to do that.
As per my understanding, you want to drop any message that does not contain WRN or ERR.
Hence it implies that you just want to send the WRN and ERR messages to logstash.
you can do it by configuring "include_lines" option
My original thought was to use a processor section but I couldn't figure out how to escape the asterisks and avoid the dreaded unknown escape sequence error.
Your suggestion to use the include_lines directive was a much better solution anyway.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.