I am new in Logstash, I could perform my first log analysis without any problem but I'm facing a situation I have not find a solution for.
So in my logs I have a path that I manage to isolate easily, but here is the thing, this path may include some ID's that I don't need.
For example I have this line :
So I would like to make those ID in bold all the same, as I care more about the kind of path, more than the specific element I deal with.
So far I managed to get all the fields seperately and my idea was to reconstruct a simplified field, by replacing the IDs to a static string in a mutate, and recreating a new field that would become for the previous example :
But at this moment the problem is that the paths I deal with don't all have the same pattern, so the IDs are not at always the same positions.
And unless I'm mistaken (?) we can't create a new field including optional fields.
So I was wondering if it's possible to change the field on the fly while we parse (within the grok). Or maybe there is another solution I haven't think about.
Thanks to all of you, and hope I have been clear enough in my explanation