@Brandon_Kobel - Please find the json data. Let me know if this works.
Both the metrics check for similar formats. The differentiating factor is the breezeEvents.Message.
{
"_index": "logstash-breeze-finesseclient-2019.10.25",
"_type": "log",
"_id": "33764717-3bae-4d0c-b494-34934e1f70fa",
"_version": 1,
"_score": null,
"_source": {
"ctxHost": "Z079",
"tags": [
"beats_input_raw_event"
],
"processID": 50356,
"application_name": "Breeze",
"@version": "1",
"occurredOn": "2019-10-25T10:47:11.3618108-05:00",
"host": {
"name": "AP01C"
},
"log": {
"format": "breeze_log",
"type": "breeze_log",
"file": {
"path": "E:\kibana\brz\logs\a0731e8d-c96c-439f-ac03-7f2c50050025.log"
}
},
"source_system_code": "BRZ",
"document_id": "33764717-3bae-4d0c-b494-34934e1f70fa",
"prospector": {
"type": "log"
},
"log.type": "breeze_log",
"input": {
"type": "log"
},
"@timestamp": "2019-10-25T15:49:03.955Z",
"application": "Breeze",
"sourceZipFilePath": "E:\Shared\Application Logs\Citrix\Breeze\10.25.2019\1467327\Z079\Logs.50356.10.48.38.zip",
"index": "logstash-breeze-finesseclient",
"logstash_timestamp": "2019-10-25T15:49:03.955Z",
"breezeEvents": {
"CurrentUser": "1467327",
"ErrorOccurred": "false",
"Message": "Breeze closed successfully."
},
"sourceZipFile": "Logs.50356.10.48.38",
"source": "E:\kibana\brz\logs\a0731e8d-c96c-439f-ac03-7f2c50050025.log",
"userName": "1467327",
"log_type": "breeze_log",
"beat": {}
},
"fields": {
"logstash_timestamp": [
"2019-10-25T15:49:03.955Z"
],
"@timestamp": [
"2019-10-25T15:49:03.955Z"
],
"sc-error-description": [
null
],
"sc-rs-code-int": [
0
],
"breezeEvents.ErrorTime": [
"2019-10-25T15:47:11.361Z"
],
"sc-error-code-type": [
null
],
"sc-rs-code-label": [
null
],
"occurredOn": [
"2019-10-25T15:47:11.361Z"
]
},
"highlight": {
"breezeEvents.Message.keyword": [
"@kibana-highlighted-field@Breeze closed successfully.@/kibana-highlighted-field@"
],
"application.keyword": [
"@kibana-highlighted-field@Breeze@/kibana-highlighted-field@"
]
},
"sort": [
1572018543955
]
}