I couldn't find any info on dissect/tokenizer relating to individual characters or wildcards. For example, if I could say make item1 3 characters long, the rest would be easy. Or if I could use a wild card for any number, I could use that as the delimiter.
Grok is the best way when no separator like example.
But filebeat has no grok processor unfortunately.
Given strings, i think script processor is best way.
- script:
lang: javascript
source: >
function process(event) {
var str1 = event.Get("extractedfield");
var str2 = str1.substr(1,3);
event.Put("item1", str2);
}
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.