I created ELK stack, and I saving postfix logs into an index. I created grok patters for mail_from, mail_to and queue_id so I store them in fields. When I'm searching a mail_from or mail_to, I need copy the queue_id and search again. Can I create a query that when I search a mail_from and mail_to then search automatic the queue_id? How?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.