all I want to do is to keep sending the first 4 lines in each request to ES noting that I read many files and each file contains different data
is there any way to do it?
Since you know what each of the lines looks like you will have to setup 4 grok filters for the first 4 lines then aggregate those together.
Then whenever the line starts with "TestCases" add the aggregated event to that event but don't define it as an end_event.
I'm not sure if this will work but it's worth a shot.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.