I want to store the contents of the log read through logstash in elasticsearch, but the contents of the log are stored in the message field. Can I use a custom template to extract the contents of the log as a certain field?
for example, is there an ip:xxxx, in the log that can extract ip and its ip as a field? I also looked at the templates on the
website and the documents on the official website. They all seemed to define a type for the field, and they didn"t use regular matching to extract specific data, so I couldn"t understand