Hi, We have problems caused by very large log messages. Can someone help me with how to formulate the following filter logic:
Logstash version is 2.3.4
Regards, David
Probably works:
filter { ruby { code => " if event['message'].length > n event.remove('message') event.tag('too_big') end " } }
Rreplace n with whatever size limit you want.
n
Hi, Thanks for that. I worked around this by using the range plugin but will test this out asap...
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.