hi,
I configured the filebeat.yml with followings:
filebeat.inputs:
-
type: log
enabled: true
paths:- D:\ECLog\dev*.log
fields:
service: dev-econtract
multiline.pattern: ^\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}.\d{4} [
multiline.negate: true
multiline.match: after
- D:\ECLog\dev*.log
-
type: log
enabled: true
paths:- D:\ECLog\uat*.log
fields:
service: uat-econtract
multiline.pattern: ^\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}.\d{4} [
multiline.negate: true
multiline.match: after
- D:\ECLog\uat*.log
-
type: log
enabled: true
.....
output.elasticsearch:
hosts: ["IP:9200"]
index: "%{[fields.service]}-%{+yyyy.MM.dd}"
I try to configure the setup.template.pattern as below:
setup.template.name: "npos"
setup.template.pattern: "dev-econtract-","uat-econtract-","dev-ekyc-","uat-ekyc-","dev-npos*","uat-npos*","dev-fim-","uat-fim-"
But unfortunately, it doesn't work.
Could anyone tell me how to configure this param to include all the indices I have defined for this beat?
Thanks