Use logstash to modify an event previously saved to elasticsearch

(Charlie) #1

Specifically, I'm trying to tag the last event prior to an exception. So, when you encounter an event that matches some criterion, go back and find the last event and then add a tag to it. Is this possible?

I assume there are more convenient ways to handle this stuff down the pipeline. Kibana, for instance, should make this pretty easy. But I'm wondering whether there's a way to do it specifically within logstash.

(Andrew Cholakian) #2

I think this would be best achieved with our Watcher product. You'd want to setup a watch that would look for exceptions, then query for the event occurring previous to that.

(system) #3

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.