Hi
I have daily results from an audit and i am not sure how i should manage the data.
All i want is to visualise the evolution of the number of documents and keep the structure
i want to be able to visualise the numberof document by type or format, the evolution of this number, ...
So i have two questions:
-
first, i am trying to parse the log file in the multiline mode with this pattern
input {
file {
path => "/tmp/input"
codec => multiline {
pattern => "^\s"
what => "previous"
}
}
}
this is working, but after i don't know what the best solution to manage the result, should i have to use split, kv ? -
Next, for the restitution should i organize the data by:
Field = nb_doc_by_type_{doc_type}, value => the count
Field = nb_doc_by_format_{doc_format}, value => the count
or maybe a hash is better ?
Sample of the audit log:
Number of Documents by Type:
Document Type Count
da_document 2,610,975
dm_cabinet 26,182
dm_document 13,687
dm_folder 5,215
dm_sysobject 2,427
dm_smart_list 1,503
da_fld_replication 1,070
da_export_config_data 513
dm_job_request 414
dm_app_ref 218
Total: -------------
2,670,487
Number of Documents by Format:
Document Format Count
excel8book 1,089,879
msw8 714,959
pdf 514,204
crtext 107,936
msw12 49,236
tiff 48,163
ppt8 29,525
zip 28,703
text 9,094
excel12book 7,692
Total: -------------
2,624,756
Thanks