You can use the add_field and add_tag common options inside any filters (and most if not all of the input and output plugins if I recall correctly). With these you can construct any shape of hash you wish at the "output" side of logstash.
If you want a little more detail, it would be helpful if you share some of your input data and your logstash configuration. We could then possibly offer other ways to achieve your end goal.
First column is a time stamp, XX can be an alert condition , condition_color can be RED, GREEN or something, the rest of the columns are descriptions about the system triggering the alert, so far
so good with that.
Then I have this filter to rename default name column names.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.