如何删除不必要的字段?类型: agent.ephemeral_id agent.id winlog.provider_guid
我试过了,但是Kibana完全不显示日志了
- drop_fields:
fields: ["date_created", "ecs.version", "agent.version", "agent.type", "agent.id"]在logstash中,我有以下几个秘密: filter.conf,input.conf,output.conf
过滤器:
filter {
if "winsrvad" in [tags] {
if [winlog][event_id] != "5136" and [winlog][event_id] !=ent_id] != "4729" and id] != "4734" {
drop { }
}
}
}发布于 2022-05-19 08:56:40
您可以使用mutate;如下所示
mutate {
remove_field => [ "date_created", "ecs.version", "agent.version", "agent.type", "agent.id"]
}https://stackoverflow.com/questions/71838253
复制相似问题