Logs Pipeline Examples
Parsing an arbitrary format using regex
vector:
logsPipeline:
extraSteps:
- name: parseRegex
transform:
type: remap
drop_on_error: false
source: |-
if .format == "unknown" {
regex_pattern = r'(?<timestamp>.*) (?<pid>\d+)'
.string_attributes = object!(.string_attributes) | parse_regex!(.content, regex_pattern)
.format = "custom-format"
}Renaming an attribute
Last updated
