everything is working fine. My data has many fields like field_a, field_b etc, which gets automatically parsed with the help of JSON codec. one of my fields field_c has another JSON data in it. Logstash also parses that and I can see the child elements as attributes in Kibana. I don't want that. I want that JSON as plain text, which means Logshash should not tokenize field_c. Is this possible?
Hi @Badger , when I looked into the documentations, I was able to see add_field, add_tag, enable_metric, id, periodic_flush, remove_field, and remove_tag options. Could you kindly tell me what should I use here, and how to use?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.