Our firewall is sending log messages to our ELK stack. Most of these messages contain a source and destination IP address.. but occasionally these values are not present. These messages are being forward via email and the values %{src} or %{dst}) are shown if these values were not in the message received.
Is there any way to either remove or replace these with a string should these values not be present in a message received.
prune can whitelist and blacklist top-level fields based on either name or value. The default configuration is to blacklist (i.e. delete) any fields for which the name matches the regexp %{[^}]+}.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.