O
O
onedmgoflthl2016-11-28 21:31:42
elasticsearch
onedmgoflthl, 2016-11-28 21:31:42

Intersecting Multiline lines in different events?

Greetings gentlemen!
Maybe someone came across. The log has blocks of events that begin and end with a key phrase. Roughly speaking, "input" - "events" - "output". Multiline perfectly stitches everything into one event, grok pulls out the necessary data. However, it happens that the "exit" does not have time to occur before a new "entrance" begins. It turns out "input1" - "input2" - "events1 and events2 mixed" - "output1" - "output2". Is it possible to somehow contrive and stitch events not by the phrase "input", but starting from the input and ending with the output? In this case, two events should have intersecting lines.
LS and ES versions 5.0, filebeat transport 5.0.1 Any hints
would be greatly appreciated!

Answer the question

In order to leave comments, you need to log in

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question