I have a field with columns A,B,C where A represents the source of the file.
Many sources send csv files to one location and the index should be according to the source.
A=source1 --> index should be "source1"
A=source2 --> index should be "source2"
Note that all rows in the csv file will contain the same info, so it's ok to choose any of the rows for creating the index.
Looks like the index is either hard-coded or derived from system fields, not from content fields. I hope it's possible because if not I'll have to engineer my solution completely differently and run multiple logstashes and separate every source to a separate location just to have separate indexes, which is a waste of resources.
Thanks in advance for any advice!