Logstash elasticsearch filter plugin

(juergen) #1

Hi there,
a new log comes in, and i query my Elasticsearch Cluster to find a match with an existing document:
if[type] == 'aaa' {
elasticsearch {
hosts => [""]
query => "SYSTNO:%{message}"
works fine, but
Now i want copy from the existing ES document (with the match SYSTNO:message) another field to the new incoming log.
fields => ["location", "newfield"]

(the fields SYSTNO and location are in the same existing document in the es-cluster)

But the the field "newfield" stays empty.?

Can somebody help me?


(Mark Walkom) #2

I'd check the document in ES to make sure that field is called what you want.

(system) #3