There was similar question about JSON messages before...
txt file--------> filebeat---------->elasticsearch
File has syslog formatted and not formatted messages from different devices (sometimes format differs a lot )
Is it possible to extract additional fields from the "message" field, when message is clear "syslog"?
Is it possible to introduce an additional fields based on conditions (regexp) of having some information in the message?
Documentation on the "processors" is very vague, tried it , no luck.
Any information would be appreciated.