Join CSV content with logs


(fellah) #1

Hi,
I want to join and map a CSV content to existent logs in elasticsearch :
My CSV contain : ClientName, ClientID
My logs contain : ClientID, ClientMessage....

I wonder if it's possible to join the CSV content so that i will have logs like this en ELK :
ClientID, ClientName, ClientMessage,...

Thx


(Guy Boertje) #2

Look at the translate filter, it can use CSV files as the lookup source. NOTE: the numeric ClientID will need to be in quotes and be the first column without a CSV header.
e.g.

"10001", Needs account renewal
"12004", Overpaid $100.00 on Jun 2017 invoice

(system) #3

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.