Need help on logstash running in docker container

Hi Team,

I have queries about logstash docker and would really appreciate if someone can help me on this?

  1. I have logstash running as docker and I need output writtten in CSV format Host server /var/ partition no in docker container.
  2. I did write output for CSV but output file is getting generated in the docker container.
  3. Plus I need certain fields only in the output not the entire message, how do I do that?
  4. As in my messages contain src_ip, dst_ip port etc.; I just need src_ip to be extracted and wondering if I could do this with logstash?

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.