Why not use a grok filter?
grok {
match => ["message", "\boutside:%{IP:ip}\b"]
tag_on_failure => []
}
if [ip] {
geoip {
...
}
}
Why not use a grok filter?
grok {
match => ["message", "\boutside:%{IP:ip}\b"]
tag_on_failure => []
}
if [ip] {
geoip {
...
}
}
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.