As there are many ways to achive similar goal using logstash filters, would like to discuss and compare between KV, Dissect, Split, and Grok, which is a better way of handling data?
Mapping & Parsing logs with consistent delimiter
Mapping & Parsing logs with inconsistent pattern
Better: If both Dissect and Grok able to achieve the same goal, should we use Dissect or Grok for a more efficient / effective parsing?
Extracting data from field (For example extracting server name fqdn, or domain from a url)
Better: If both Split / Grok able to achive the goal, which will be more efficient to use?
Anyone have any example would be nice to discuss together too!!