You just need to add the grok and mutate+add_field to convert [foo] to the fields that you want. It's really ugly code, but I do not have time to write something prettier right now.
Is there a way to grok first for the relevant parts (i.e. have 3 separate groks for aX, bY and cY, where the last two should be optional), put everything in an event (i.e. have an event that has aX, bY and cY as fields) and then clone based on the resulting event?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.