Dear, collegues pls help me!
I have input log following format:
Exm:
1 value
1 100
1 value1
2 mean
2 text
2 something
3 SOAP
3 example_text
I need to convert output log in Real-time in the foloving view:
1 value 100 value1
2 mean text something
3 SOAP example_text
Well, i wrote grok and mutate filter in my logstash:
if "gateway_ssl" in [tags] {
mutate {
gsub => ["message","\t", " "]
add_tag => ["mutate"]
}
grok {
match => {
"message" => ["%{BACULA_DEVICE:transaction_id} ?%{GREEDYDATA:text_message}"]}
add_tag => ["grokked"]
overwrite => [ "message" ]
} #grok
}#if_gateway
Could you help me to write aggregate filter for my task?
Thank you a lot!