logstash-filter-grok
logstash-filter-grok copied to clipboard
Add an 'output_objects' config that builds an object for each grok performed
Previous functionality grouped each field by name meaning you lost all context about your events:
{
"logsource": [
"evita",
"evita"
],
"message": [
"connect from camomile.cloud9.net[168.100.1.3]",
"connect from steve.cloud9.net[168.100.1.4]"
],
...
}
to:
{
"syslogs": [
{
"logsource": "evita",
"message": "connect from camomile.cloud9.net[168.100.1.3]",
...
},
{
"logsource": "evita",
"message": "connect from steve.cloud9.net[168.100.1.4]",
...
}
]
}