Sure, do you mean something like this? If so, I will send 2-3 more samples!
{
"took" : 7,
"timed_out" : false,
"_shards" : {
"total" : 1,
"successful" : 1,
"skipped" : 0,
"failed" : 0
},
"hits" : {
"total" : {
"value" : 10000,
"relation" : "gte"
},
"max_score" : 1.1814985,
"hits" : [
{
"_index" : "dispatcher-app-logs",
"_type" : "_doc",
"_id" : "zU4srHAB6A9xeN1mnOv3",
"_score" : 1.1814985,
"_source" : {
"@version" : "1",
"@timestamp" : "2020-03-05T19:28:43.291Z",
"ecs" : {
"version" : "1.1.0"
},
"host" : {
"name" : "mehak-VirtualBox"
},
"agent" : {
"type" : "filebeat",
"hostname" : "mehak-VirtualBox",
"ephemeral_id" : "9b0a94c4-4cf8-4347-97d7-19594af4d99e",
"version" : "7.4.0",
"id" : "bad135c8-d359-4936-b515-79eb4bb24630"
},
"message" : " <additionalinfo />",
"log" : {
"file" : {
"path" : "/home/mehak/Documents/filebeat-7.4.0-linux-x86_64/logs/logz.log"
},
"offset" : 8679173
},
"tags" : [
"beats_input_codec_plain_applied",
"_grokparsefailure"
],
"fields" : {
"log_type" : "dispatcher-app-logs"
}
}
},
{
"_index" : "dispatcher-app-logs",
"_type" : "_doc",
"_id" : "zk4srHAB6A9xeN1mnOv9",
"_score" : 1.1814985,
"_source" : {
"@version" : "1",
"@timestamp" : "2020-03-05T19:28:43.292Z",
"agent" : {
"type" : "filebeat",
"hostname" : "mehak-VirtualBox",
"ephemeral_id" : "9b0a94c4-4cf8-4347-97d7-19594af4d99e",
"version" : "7.4.0",
"id" : "bad135c8-d359-4936-b515-79eb4bb24630"
},
"host" : {
"name" : "mehak-VirtualBox"
},
"ecs" : {
"version" : "1.1.0"
},
"message" : " <clientReferenceKey>EZMxzk4quI</clientReferenceKey>",
"log" : {
"file" : {
"path" : "/home/mehak/Documents/filebeat-7.4.0-linux-x86_64/logs/logz.log"
},
"offset" : 8679195
},
"tags" : [
"beats_input_codec_plain_applied",
"_grokparsefailure"
],
"fields" : {
"log_type" : "dispatcher-app-logs"
}
}
},
{
"_index" : "dispatcher-app-logs",
"_type" : "_doc",
"_id" : "z04srHAB6A9xeN1mnesE",
"_score" : 1.1814985,
"_source" : {
"@version" : "1",
"@timestamp" : "2020-03-05T19:28:43.292Z",
"ecs" : {
"version" : "1.1.0"
},
"host" : {
"name" : "mehak-VirtualBox"
},
"agent" : {
"version" : "7.4.0",
"hostname" : "mehak-VirtualBox",
"type" : "filebeat",
"ephemeral_id" : "9b0a94c4-4cf8-4347-97d7-19594af4d99e",
"id" : "bad135c8-d359-4936-b515-79eb4bb24630"
},
"message" : " <Category>Dispatch</Category>",
"log" : {
"file" : {
"path" : "/home/mehak/Documents/filebeat-7.4.0-linux-x86_64/logs/logz.log"
},
"offset" : 8679250
},
"tags" : [
"beats_input_codec_plain_applied",
"_grokparsefailure"
],
"fields" : {
"log_type" : "dispatcher-app-logs"
}
}
},
{
"_index" : "dispatcher-app-logs",
"_type" : "_doc",
"_id" : "0E4srHAB6A9xeN1mnesJ",
"_score" : 1.1814985,
"_source" : {
"@version" : "1",
"@timestamp" : "2020-03-05T19:28:43.292Z",
"agent" : {
"version" : "7.4.0",
"hostname" : "mehak-VirtualBox",
"type" : "filebeat",
"ephemeral_id" : "9b0a94c4-4cf8-4347-97d7-19594af4d99e",
"id" : "bad135c8-d359-4936-b515-79eb4bb24630"
},
"host" : {
"name" : "mehak-VirtualBox"
},
"ecs" : {
"version" : "1.1.0"
},
"message" : " <externalcategory></externalcategory>",
"log" : {
"file" : {
"path" : "/home/mehak/Documents/filebeat-7.4.0-linux-x86_64/logs/logz.log"
},
"offset" : 8679283
},
"tags" : [
"beats_input_codec_plain_applied",
"_grokparsefailure"
],
"fields" : {
"log_type" : "dispatcher-app-logs"
}
}
},
{
"_index" : "dispatcher-app-logs",
"_type" : "_doc",
"_id" : "0U4srHAB6A9xeN1mnesP",
"_score" : 1.1814985,
"_source" : {
"@version" : "1",
"@timestamp" : "2020-03-05T19:28:43.292Z",
"agent" : {
"version" : "7.4.0",
"hostname" : "mehak-VirtualBox",
"type" : "filebeat",
"ephemeral_id" : "9b0a94c4-4cf8-4347-97d7-19594af4d99e",
"id" : "bad135c8-d359-4936-b515-79eb4bb24630"
},
"ecs" : {
"version" : "1.1.0"
},
"host" : {
"name" : "mehak-VirtualBox"
},
"message" : " <targetpartyid>100</targetpartyid>",
"log" : {
"file" : {
"path" : "/home/mehak/Documents/filebeat-7.4.0-linux-x86_64/logs/logz.log"
},
"offset" : 8679324
},
"tags" : [
"beats_input_codec_plain_applied",
"_grokparsefailure"
],
"fields" : {
"log_type" : "dispatcher-app-logs"
}
}
},
{
"_index" : "dispatcher-app-logs",
"_type" : "_doc",
"_id" : "0k4srHAB6A9xeN1mnesV",
"_score" : 1.1814985,
"_source" : {
"@version" : "1",
"@timestamp" : "2020-03-05T19:28:43.292Z",
"ecs" : {
"version" : "1.1.0"
},
"host" : {
"name" : "mehak-VirtualBox"
},
"agent" : {
"version" : "7.4.0",
"hostname" : "mehak-VirtualBox",
"type" : "filebeat",
"ephemeral_id" : "9b0a94c4-4cf8-4347-97d7-19594af4d99e",
"id" : "bad135c8-d359-4936-b515-79eb4bb24630"
},
"message" : " <operationtype>ACTIVITY</operationtype>",
"log" : {
"file" : {
"path" : "/home/mehak/Documents/filebeat-7.4.0-linux-x86_64/logs/logz.log"
},
"offset" : 8679362
},
"tags" : [
"beats_input_codec_plain_applied",
"_grokparsefailure"
],
"fields" : {
"log_type" : "dispatcher-app-logs"
}
}
},
{
"_index" : "dispatcher-app-logs",
"_type" : "_doc",
"_id" : "004srHAB6A9xeN1mnesd",
"_score" : 1.1814985,
"_source" : {
"@version" : "1",
"@timestamp" : "2020-03-05T19:28:43.292Z",
"ecs" : {
"version" : "1.1.0"
},
"agent" : {
"version" : "7.4.0",
"hostname" : "mehak-VirtualBox",
"type" : "filebeat",
"ephemeral_id" : "9b0a94c4-4cf8-4347-97d7-19594af4d99e",
"id" : "bad135c8-d359-4936-b515-79eb4bb24630"
},
"host" : {
"name" : "mehak-VirtualBox"
},
"message" : " <userid>-101</userid>",
"log" : {
"file" : {
"path" : "/home/mehak/Documents/filebeat-7.4.0-linux-x86_64/logs/logz.log"
},
"offset" : 8679405
},
"tags" : [
"beats_input_codec_plain_applied",
"_grokparsefailure"
],
"fields" : {
"log_type" : "dispatcher-app-logs"
}
}
},
{
"_index" : "dispatcher-app-logs",
"_type" : "_doc",
"_id" : "1E4srHAB6A9xeN1mnesl",
"_score" : 1.1814985,
"_source" : {
"agent" : {
"version" : "7.4.0",
"hostname" : "mehak-VirtualBox",
"type" : "filebeat",
"ephemeral_id" : "9b0a94c4-4cf8-4347-97d7-19594af4d99e",
"id" : "bad135c8-d359-4936-b515-79eb4bb24630"
},
"@version" : "1",
"@timestamp" : "2020-03-05T19:28:43.292Z",
"host" : {
"name" : "mehak-VirtualBox"
},
"ecs" : {
"version" : "1.1.0"
},
"message" : " <IncidentId>24750142</IncidentId>",
"log" : {
"file" : {
"path" : "/home/mehak/Documents/filebeat-7.4.0-linux-x86_64/logs/logz.log"
},
"offset" : 8679430
},
"tags" : [
"beats_input_codec_plain_applied",
"_grokparsefailure"
],
"fields" : {
"log_type" : "dispatcher-app-logs"
}
}
},
{
"_index" : "dispatcher-app-logs",
"_type" : "_doc",
"_id" : "1U4srHAB6A9xeN1mness",
"_score" : 1.1814985,
"_source" : {
"@version" : "1",
"@timestamp" : "2020-03-05T19:28:43.292Z",
"ecs" : {
"version" : "1.1.0"
},
"host" : {
"name" : "mehak-VirtualBox"
},
"agent" : {
"version" : "7.4.0",
"hostname" : "mehak-VirtualBox",
"type" : "filebeat",
"ephemeral_id" : "9b0a94c4-4cf8-4347-97d7-19594af4d99e",
"id" : "bad135c8-d359-4936-b515-79eb4bb24630"
},
"message" : " <externalticketstatus></externalticketstatus>",
"log" : {
"file" : {
"path" : "/home/mehak/Documents/filebeat-7.4.0-linux-x86_64/logs/logz.log"
},
"offset" : 8679467
},
"tags" : [
"beats_input_codec_plain_applied",
"_grokparsefailure"
],
"fields" : {
"log_type" : "dispatcher-app-logs"
}
}
},
{
"_index" : "dispatcher-app-logs",
"_type" : "_doc",
"_id" : "1k4srHAB6A9xeN1mnesx",
"_score" : 1.1814985,
"_source" : {
"@version" : "1",
"@timestamp" : "2020-03-05T19:28:43.292Z",
"agent" : {
"ephemeral_id" : "9b0a94c4-4cf8-4347-97d7-19594af4d99e",
"hostname" : "mehak-VirtualBox",
"version" : "7.4.0",
"type" : "filebeat",
"id" : "bad135c8-d359-4936-b515-79eb4bb24630"
},
"ecs" : {
"version" : "1.1.0"
},
"host" : {
"name" : "mehak-VirtualBox"
},
"message" : " <result>Success</result>",
"log" : {
"file" : {
"path" : "/home/mehak/Documents/filebeat-7.4.0-linux-x86_64/logs/logz.log"
},
"offset" : 8679516
},
"tags" : [
"beats_input_codec_plain_applied",
"_grokparsefailure"
],
"fields" : {
"log_type" : "dispatcher-app-logs"
}
}
}
]
}
}