They all contain public fields: dst_addr, sub_type, vsid;
Can I filter out public fields using only one grok regular expression statement and send them to elasticsearch??
i just want to send sub_type and dst_addr to the elasticsearch,as a field index.The order of the log content is different each time, but both contain this field.Can this help me?
If it can, can you give me an example? Thank you very much.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.