Hello!
I have a Windows server, it is winlogbeat, data is sent to Elasticsearch via Logstash.
I'm getting data from the security log and sysmon.
All this data is sent to the index "index1". But there is data, which have event.action equals "Test". I want to receive data with event.action="Test" to "index2".
My output.conf for Logstash now:
output { if "winserv1" in [tags { elasticsearch { hosts => "localhost:9200" index => "index1-%{+YYYY.MM.dd}" } } }
Help me pleas.
I try:
output { if "winserv1" in [tags { elasticsearch { hosts => "localhost:9200" index => "index1-%{+YYYY.MM.dd}" } }else if "Test" in [event.action]{ elasticsearch { hosts => "localhost:9200" index => "index2-%{+YYYY.MM.dd}" } } }
But it doesn't work..