I am trying to read events from a s3 bucket and index them into elasticsearch. Everything works fine if I have a single input and output and I used to be able to use a conditional like
if [metricset] {
elasticsearch {
hosts => ["elasticsearch:9200"]
index => "metricbeat-%{+YYYY.MM.dd}"
}
}
however now that type field is gone I am having trouble isolating the metricbeat events to their own index...
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.