ELK version 6.2.3
Sample data as below
{'_links': {'doc': {'href': '/mgmt/docs/status/MQSystemResources'}, 'self': {'href': '/mgmt/status/default/MQSystemResources'}}, 'MQSystemResources': {'HAStatus': 'Online', 'TotalErrorsStorage': 16179, 'UsedStorage': 528408, 'UsedErrorsStorage': 495, 'TotalTraceStorage': 32256, 'UsedTraceStorage': 691, 'TotalStorage': 3051008, 'HAPartner': 'MQA1 (Online)'}}
Logstash config has a Input Beats and Output section.
Expectation is to have the Keys defined in ES< and searchable in kibana.
When looking in kibana, it is only a message field.
stdout from logstash looks as
{
"@timestamp" => 2018-06-07T05:01:56.544Z,
"prospector" => {
"type" => "log"
},
"message" => "{'_links': {'doc': {'href': '/mgmt/docs/status/MQSystemResources'}, 'self': {'href': '/mgmt/status/default/MQSystemResources'}}, 'MQSystemResources': {'HAStatus': 'Online', 'TotalErrorsStorage': 16179, 'UsedStorage': 528408, 'UsedErrorsStorage': 495, 'TotalTraceStorage': 32256, 'UsedTraceStorage': 691, 'TotalStorage': 3051008, 'HAPartner': 'MQA1 (Online)'}}",
"@version" => "1",
"source" => "/var/log/om.log",
"offset" => 363,
"fields" => {
"topic" => "dummy",
"logsource" => "dummy"
},
"beat" => {
"hostname" => "elk",
"version" => "6.2.3",
"name" => "elk"
}
}
How do i have the Key values in ES indexed.