mutate 字段替换:
mutate 过滤允许你执行一般的转换,可以rename,remove,replace 和修改事件中的字段
简介 这个插件支持下面的配置选项:
add_field
Value type is hash
Default value is {}
如果过滤器成功,可以增加任意字段到这个事件
字段名可以是动态的,并包含使用%{Field}的事件部分。
mutate {
add_field =>["newmessage","%{type},%{message}"]
}
[elk@node2 conf]$ logstash -f logstash04.conf
!!! Please upgrade your java version, the current version '1.7.0_45-mockbuild_2013_11_22_18_30-b00' may cause problems. We recommend a minimum version of 1.7.0_51
Settings: Default pipeline workers: 4
Pipeline main started
{
"@timestamp" => "2020-10-08T13:28:53.823Z",