Hi cisaksen,
grok {
match => [ "message", "(?<httphost>^http://./.?$) "]
}
? will add the new field with the regex you define behind it, like shown above
Hi cisaksen,
grok {
match => [ "message", "(?<httphost>^http://./.?$) "]
}
? will add the new field with the regex you define behind it, like shown above
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.