I am sending logs from Windows server using winlogbeat to logstash (6.6). The field that I am trying to split has 2 IP addresses separated by a comma. How can I go about and create 2 new fields (FirstIP and SecondIP)? There will only ever be a max of 2 IPs, but sometimes only 1.
Field:
event_data.param5
I tried doing something like this but filters are not my strong point by any means.
but it is a pretty narrow definition of an email address. It does not match UUCP bang paths, for example, like "mcvax!foo"@somehost.com, and will not recognize TLDs in non-Latin characters, so if your email address is in the онлайн domain it is not going to match it.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.