Hello,
this is the filter I am using
filter {
if (([message] =~ /Interface/)) {
dissect {
mapping => { "message" => "%{syslog_timestamp} %{+syslog_timestamp},%{} %{} %{device_type} %{hostname}-%{h1}/%{} %{kernel_logs}" }
}
}
}
Hello,
this is the filter I am using
filter {
if (([message] =~ /Interface/)) {
dissect {
mapping => { "message" => "%{syslog_timestamp} %{+syslog_timestamp},%{} %{} %{device_type} %{hostname}-%{h1}/%{} %{kernel_logs}" }
}
}
}
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.