Hello,
I'm encounter some issue on testing nested field after a grok.
grok { match => { "message" => [ ".*(?<event.action>test) xxxx %{DATA:[name]}" ] } if ( "" in [event][action] ) { mutate { remove_field => "message" } }
But it never remove my message field, wheter [event][action] exist or not.