t source /mnt/logs/core1ui1/Log_2017-01-13-12.log
My message gets inserted as above. I would like to add a tag (or a field) that tells me that source contained core1ui1. My current filter is as below but I have got neither a tag (nor a field) when it executes.
if [ source ] =~ /core1ui1/ {
mutate {
add_tag => [ "WebService" ]
#add_field => { "service" => "WebService" }
}
}
thank you