I have put the multiline processing in filebeat and it's working. At logstash, I want to aggregate multiple multiline events if the events contain same value for key2. I have pasted a sample message above.
If I understand correctly you are trying to group multiple log lines at Logstash also, based on some value which matches in the previous log event. Is that correct?
Edit: If that is the case am not sure how to do it. I am afraid it is not even possible I think.!!
Above log lines get combined by beat and sent to logstash as 1 event. I will receive multiple like this that need to be aggregated based on dataId key.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.