I have this logs and need aggregate to selected fields:
I don´t have error log, but I not see aggregated log´s
My logstash aggregate config:
if [type] == "Logs-Clientes" {
aggregate {
task_id => "%{user}%{src_address}%{src_port}%{dst_address}%{dst_port}"
code => "map['c_bytes'] ||= 0 ; map['c_bytes'] += event.get('bytes')"
timeout => 5
timeout_tags => ['_aggregatetimeout']
timeout_code => "event.set('bytes', map['c_bytes'])"
}
}
if "_aggregatetimeout" not in [tags] {
drop {}
}
Thank´s