We have a custom App and are trying define some Log Pattern based on some custom messages. At our Demo App where we type and submit any kind of test message, Filebeat outputs to ES and message appears at message field.
However, when I try create some Visualization and use the "message" field over Terms, is not available.
What Can I do to have the message string show up as a valid field to create Visualizations on Kibana?
I have explored the following link, but not sure what condition or parameter to best achieve this goal. https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html
We are testing this at Openshift 4.x ( OCP on-preminse ) and deploying filebeat as daemonset.
Example of custom messages a Application can generate.
"App01 - WebServer is starting"
"App01 - WebServer is up and running"
"App01 - WebServer is scaling 2 pods"
"App02 - Database is will be restarted in 5 minutes"
"App02 - Database is up and running"
"App02 - Database is refreshing tables"