In the below input, we need to filter out “COUNT_XXX123=1,SUCCESS_XXX123=1” even if we don’t have “sellerId=XXX123” field available.
Input:
OtherMessages1=1,sellerId=XXX123,COUNT_XXX123=1,SUCCESS_XXX123=1,OtherMessages2=2
Filter:
filter {
kv {
field_split => ","
}
mutate {
remove_field => [ "COUNT_%{WORD}", "SUCCESS_%{sellerId}"]
}
}
In above case it is only filtering SUCCESS_XXX123 but not COUNT_XXX123.