Hello,
Logstash version: 6.8.23
data
message: cmd_logger_api.c(260) 10987641 %% INFO [CLI:backupguy:10.0.1.254] User has logged out
type: rsyslog
Logstash filter:
filter {
if "backupguy" in [message] { drop {} }
}
Problem:
I still seem to be getting the string backupguy in the message field created in Elasticsearch anyone have any ideas why?