In the csv filter plugin there is a configuration option called
skip_empty_columns.
I would like to use the same functionality with Windows Eventlogs.
That it, remove fields that are empty.
Right now they only say "-"
Thaaaanks
In the csv filter plugin there is a configuration option called
skip_empty_columns.
I would like to use the same functionality with Windows Eventlogs.
That it, remove fields that are empty.
Right now they only say "-"
Thaaaanks
Sounds like the prune filter could help.
Awesome.. will look into that. Thanks Mange. 
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.