Set up custom mapping


#1

Hi there.

I did not find an existing topic about this, so...

The log to be analyzed looks like this:

2012-01-01|SEVERE|System error|NullPointerException|user1
2012-01-01|INFO||Logged In|user2
2012-01-01|SEVERE|System error|AuthenticationException|user3
...
and so on..

What kind of command should I make in console to make proper mappings for this file?
Any other things to be notified? The JSON conversion for the file is out of question.

Br
Wins


(David Pilato) #2

The JSON conversion for the file is out of question.

Why?


#3

Cause I say so :slight_smile:. It’s the last option.


(David Pilato) #4

That's not a valid answer.
Why not using ingest node to transform text as structured document or logstash ?


#5

So there is no way to set up custom mapping command for this kind of log file? Just say yes or no, thanks.

Wins


(system) #6

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.