I have a field "host" that looks like this:
"aaa-b1.site.com"
I want to add a new field "env" containing only "b1". My filter:
grok {
match => {
"message" => "url:%{DATA:host}"
}
add_field => { "env" => ".*%{DATA:env}\.site\.com" }
How can I get a new field out of an existing field?