Good afternoon. Please help with the following question. I use the following standard output config:
elasticsearch {
hosts => ["localhost:9200"]
manage_template => false
index => "syslog-%{+YYYY.MM.dd}"
}
In Logstash filter:
geoip {
source => "[http][access][remote_addr]"
target => "[geoip]"
}
I create field geoip in syslog-*. Everything works well and I can use the geo map in Kibana, but only until a new day comes. After a new file with a different date appears, the field conflict occurs (pictures in attach):
please help solve this problem, thank you.