Sending JSON to Elasticsearch


I have JSON logs that i would like to send to ElasticSearch with filebeat, but when i do, all the fields in the JSON do not actually become searchable fields in ES/Kibana. How do i make the fields from the JSON into search fields that i can use with timelion, visualizations, etc?

(Christian Dahlqvist) #2

You can use the decode_json_fields processor in Filebeat.

(system) #3

