2016-02-17 21 views

回答

1

是的,只要添加以下mutate filter在Logstash配置:

filter { 
mutate { 
    remove_field => [ "@version", "@timestamp", "message" ] 
} 
} 
1

是的,你可以添加和刪除字段刪除使用後你的conf文件片段。

filter { 
    mutate { 
    remove_field => [ "@timestamp", "message", "@version" ] 
    } 
} 

添加新的字段使用下面的代碼段。

filter { 
    mutate { 
    add_field => { "foo_%{somefield}" => "Hello world, from %{host}" } 
    } 
}