Hi all,
i'm trying to accomplish one very simple thing, but i'm now stuck.
This is my basic logstash pipeline:
input {
beats {
port => 5044
}
}
### FILTER SECTION ###
filter {
if "cms-access" in [tags] {
grok {
match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{DATA:app} %{GREEDYDATA:address} %{IP:ip} - - %{NUMBER:response} %{GREEDYDATA:request} %{QS:agent}" }
}
}
}
output {
if "cms-access" in [tags] {
elasticsearch {
hosts => ["es_data1", "es_data2"]
index => "logstash-cms-access-%{+YYYY.MM.dd}"
}
}
}
But, obviously, nothing is ingested in Elasticsearch (i tried without if condition and it works).
Thanks