I have a log message with a format like:
status : name message ; status: name message ; status: name message ; status: name message.....
I need to split based on the semicolon, and create separate Elasticsearch documents that have fields for each of status, name and message. For example, if my log message was like this:
WARNING: A B ; CRITICAL: C D ; OK E F ; CRITICAL G H
Then I would need four different documents. The first document would have three fields, where status is WARNING, name is A and message is B. The second document would have status CRITICAL, name C and message D, and so on.
How do I do this?
