How did you add the taskStarted and taskEnded tags to the events? Something like this?...
if [ent_sort] == "sortie" { mutate { add_tag => [ "taskEnded" ] } }
How did you add the taskStarted and taskEnded tags to the events? Something like this?...
if [ent_sort] == "sortie" { mutate { add_tag => [ "taskEnded" ] } }
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.