I am using ELK GA 5.0.0. In my index, I have a string field named name. I want to create a field named category based on the value of name. Below is the pseudo code;
I more recent versions you should be able to do this using a scripted field using Painless. Not sure whether but is possible in earlier versions. In general it would however probably be faster and more efficient to add this as a field at index time.
But actually, my logstash is generic and taking much cpu already. Thought of adding this to logsatsh, so that I can easily modify my data accordingly, but there are reasons. My only possible hope is scripted field now, thats y
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.