I'm currently working on an ElasticSearch project that monitors LDAP logs.
In the LDAP logs, related events shares the same id (connection_number). I was wondering is there is a solution to regroupe the various fieds in different documents that shares the same id.
Most of the time between a BIND and an UNBIND thousands of lines and operation would come in between, and even other conn with different conn IDs. So I don't know if it's a viable solution.
I thought about adding the dn ( from the BIND ) to each line that has the same conn ID. But I don't if/how I can implement it in logstash.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.