I have a big log CSV file, receiving logs from different equipments.
My logstash read the lines and send to a daily index.
I need to keep the last equipment report in a different index.
Too many slow visualizations aggregate top hit to get this value, but I think that I don't need to do this.
My plan is:
import logs normally as today with logstash-*
create a second index 'last_report', where id is equipment_id.
So, every new line actually will be a update on the last_report index.
Is this possible with logstash, or did I need to think in a different way?