Lot of fields


(Julien Lavocat) #1

Hi,

My log files are in this format :
https://pastebin.com/6aWqWUiY

so I use Filebeat to feed elasticsearch with my logs but when I create an index template in Kibana I have 305 fields and some are related to apache2, nginx, ...

I don't need all those fields so is it possible to remove them without using Logtash ?

Sorry for my bad English ^^


(David Pilato) #2

Sorry for my bad English ^^

Which part is bad? No worries... I'm not native either. BTW as your name sounds french, you might want to know that we have a dedicated forum en fran├žais in #in-your-native-tongue:discussions-en-francais

I don't need all those fields so is it possible to remove them without using Logtash ?

You can probably modify the template in filebeat by changing fields.yml.


(system) #3

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.