Filebeat mssql

I'm trying to transfer the mssql log to elastic. This also works so far, but I get the errors all in text fields


How can I split this field into individual fields or how can I search for certain keywords in this field

Thanks
Marcel

Hey @Marcel_Palme,

Are you using the mssql module?

If that's the case it may need some enhancements to better parse these logs, could you share some of the log lines you would expect to see better parsed?

yes i use the mssql module. the configuration currently looks like this - only the paths to the log files are in it. I get the information, yes - see the picture in my first post, but I can't search through it or filter it

Please don't post pictures of text or code. They are difficult to read, impossible to search and replicate (if it's code), and some people may not be even able to see them :slight_smile: