Hi,
I'm trying to filter a second type of messages coming in my input queue.
The difference between messages is that in the second type of messages the log is embedded in a JSON as value of the "Message" field. I configured the JSON filter plugin as follow:
As expected the JSON parsed value of "Message" is placed in the new field "doc". Now, I'm struggling to further parse the "doc" nested fields. I'm using the add_field parameter to do this, without success tho.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.