Parse the data using filebeat

Good afternoon.

I'm having a hard time filtering information from filebeat / logstash.

Here's the current scenario I'm using:

filebeat: Installed on 06 servers to collect a log consisting of multi-lines, attached an example of how it is found
logstash: receives the filebeat information and sends to the elastic
elasticsearch: receives the information in NFS and the data is viewed in Kibana

Logstash by default reads one line at a time and because it has several rows it does not understand that it is part of the same block, as my log is multi-line, when doing the search it can not understand and the data is separated which makes it difficult in information.

Could someone show me some configuration example of how I could do these tests?

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.