Send to multiple elasticsearch index with different fields

(Wang Xiang Ustc) #1

I have log like this:

"info":"just for search",
"response": {
"code": 200,
"status": ok,
"cmd": "login"

and I want to send the total log into index A for text search, and send only the code/status/cmd to another index B for aggregation。

so, how to do this?

(Magnus Bäck) #2

You need to use a clone filter to split each event in two. Then use different filters on each copy of the message and send them to different outputs.

(Wang Xiang Ustc) #3

what is clone filter? means two filter in one config file?

(Wang Xiang Ustc) #4

Ok, I have already know what is clone . Thank you !

(system) #5

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.