I am monitoring a bunch of servers using the ELK stack. I want to monitor custom Java processes that are being run from jars on those servers. I am trying to split the line graph using the
system.process.cmdline.keyword feature. But
system.process.cmdline.keyword field is absent for some types of command while the corresponding
system.process.cmdline is present. I am guessing
.keyword conversion logic fails in these cases. Does not work for this.
Works for this. Please notice the difference in command line field in both the cases.
Any help here is appreciated. Been stuck over this for long