I tried to forward some log to ELK from a device. I find all event merge into one message. May I know is it possible to separate into different event? here's the log example. Thanks
The log is sent from a system through tcp. The system only can be configured destination ip and protocol (TCP / UDP), cannot add a new line. May I know using UDP can solve the issue?
Now I tried to use codec=> line {delimiter => "<51>"} to separate each record and succeed. But I also want to separate each record based on "<52>". Can I do like this?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.