Hi people, i have a elk working with the logs of a samba file server
I want make graphics with unlink file but i have a lot of tmp files, i want filter this archives, i read a bit and only find placing "- " but nothing happend, i have the same result.
example of a log:
domain\admin | 192.168.1.30|hostname|domain|unlink|541b4a62.tmp
I want to show only the files actually deleted by the user
unlink is how show the deletion and 541b4a62.tmp is the file
otrher example of write a file would:
domain\admin | 192.168.1.30|hostname|domain|pwrite|elasticsearch.conf
i can show all of the unlink log, but i need filter the .tmp
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.