I used to have a single input to logstash which I then parsed through conditional statements. I am now adding another input that won't apply to any of the prior work.
-
Can I just add tags to the input and add another large if else conditional around all of my prior parsing so it skips it?
-
I want to put this into elasticsearch in a separate index with a separate template. Do I still send both outputs to IP:9200?
-
I'm also using shield does that effect any of this?
Any input would be helpful. I pay for support however, my support guy is busy until monday and i'd really like to work on this today.
Thanks,
Jack West