Normalizer


(Artem) #1

Hi!

I parse IIS logs with Filebeat. Field " iis.access.referrer" has values with GET-method parametes. Example: "https://www.google.com/search?q=elasticsearch"
I want to see only host name ("www.google.com") in Kibana (term aggregation). In nornalizer I can not set custom regex pattern.
How I can do it?

Elasticsearch 6.3.0
Filebeat 6.4.1

Thanks!


(Pier-Hugues Pellerin) #2

Hello, I think modifying the IIS module ingest pipeline and the gsub processor to create a new normalized field with only the host would be the way to do it.

I think you want to sum the request from a specific host?


(Artem) #3

Thank you very much! I will try it.


(system) #4

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.