How to Differentiate Logs from a Host

(Shashi Lanka) #1


I have a test service instance on a host where a log-stash agent is configured. This logs are stashed to a common elastic server. Now this will be test service instance will be cleaned up and another test service instance will be installed and log-stash agent is reconfigured against the same elastic server. Now my question is whether there is a way to say that the logs from same host shown in elastic server are from specific test instance(with unique id).

(Magnus Bäck) #2

You could add a tag or other field to the events originating on the test instance. A mutate filter would do.

(Shashi Lanka) #3

Thanks. Can you please quote me some examples.

(Magnus Bäck) #4

The mutate filter's documentation contains examples.

(system) #5

