grok {
match => { "message" => "%{HTTPD_COMBINEDLOG}" }
remove_field => [ "message" ]
}
useragent {
source => "agent"
target => "ua"
remove_field => [ "agent" ]
remove_field => [ "ua.patch" ]
remove_field => [ "ua.build" ]
}
配置如上,agent
字段删除成功,但是ua.patch
和ua.build
删除失败,谁知道什么原因请告诉我,谢谢。