output {
if [fields][log_type] == "sesvg1" {
elasticsearch {
action => "index"
hosts => "http://localhost:9200"
index => "sesvg1newbeat1"
}
} else if [fields][log_type] == "sesvg2" {
elasticsearch {
action => "index"
hosts => "http://localhost:9200"
index => "sesvg2newbeat2"
}
}
}
here are configurations and I got see any indexes getting created in kibana I have tried with single log file i am abele to process and see the data getting populated
@sandeepnarla22322 Hello, it will also help to see the log from filebeat, if you start filebeat with ./filebeat -v -e -d "*" -c yourconfig.yml, the log should tell us what filebeat see and if it can connect to Logstash.
I have a scenario where I have to process logs from 100 prod nodes at the same time and logs will be rotated every five minutes
I am trying test this scenario by dumping a new file from a new file into the folder every five minutes to see if it is processing the logs but I don't see my logs being processed
###################### Filebeat Configuration Example #########################
This file is an example configuration file highlighting only the most common
options. The filebeat.full.yml file from the same directory contains all the
supported options with more comments. You can use it as a reference.
You can find the full configuration reference here:
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.