Hello !
I was wondering if it is possible to embed the content of a field to a new "structured field" ?
For example, from a JDBC entry, I've got a column named message which contains informations with the following format:
CONFIRM;userId:58428;status:DONE;...
With a grok match, I succeeded to split the message column into several new document fields :
"_index": "demo",
"_type": "demologs",
"_id": "AVulVdwqUVyhaHL536Vw",
"_score": 1,
"_source": {
"date": "2015-09-27T12:21:58.000Z",
"amount": "58.2",
"type": "CONFIRM",
"userId": "58428",
"status": "DONE",
} ...
Date/Amount come from other column of the table.
But is it possible to create a field that encapsulate all message informations without manually use the add_field feature ?
"_index": "demo",
"_type": "demologs",
"_id": "AVulVdwqUVyhaHL536Vw",
"_score": 1,
"_source": {
"date": "2015-09-27T12:21:58.000Z",
"amount": "58.2",
"message" : {
"type": "CONFIRM",
"userId": "58428",
"status": "DONE",
},
} ...
Thanks!