How to get specific pieces of log instead of entire log


(Camilo Riviere) #1

Hello, I was wondering on how I would go about taking only specific pieces of data from a log instead of passing the entire log to elasticsearch. Is there a way to currently do this?


(Ed) #2

Logstash has to read the entire file, but you can use filters to drop data you don't want
https://www.elastic.co/guide/en/logstash/current/plugins-filters-drop.html

filter{
if [message] =~/DEBUG/) {
drop{}
}
}


(system) #3

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.