I have the following issue that I hope to get some help to resolve
. I ingest a log file using filebeat
. I defined inside elasticsearch grok and kv statements to split incoming data into separated fields
. If I have field that II want to further split down to different field, how can I do it?
. Is there a way to apply a regular expression to a field to determine a match and split this field into different values?
. Can I assign the new split values different fields?
I have a field --
navlog.context.filename : https://xxx.yyy.com/NA/GEN4/LANDMARK/version.properties
I want to split the above field into:
Thank you in advance for your help.