Logmessage map to tags or fields

(Jay) #1

Continuing the discussion from Any Help Un-structure log message to map structure message in Logstash:

(Magnus Bäck) #2

This is a Logstash question so I'm not sure why you want to continue the discussion in the Elasticsearch group.

(Jay) #3

i thought it stored in elasticsearrch so same mapping need in elasticsearch

(Magnus Bäck) #4

Yes, Logstash can store data in Elasticsearch. If you use the grok filter as described in the other thread you'll get your log entries stored in Elasticsearch with separate fields for the timestamp, log level, class name, and so on. No further action is necessary on the Elasticsearch side.

