mpolitaev
(Mihail Politaev)
August 17, 2017, 12:54pm
1
Hi team!
Is there a error will be if i name my logstash’s parsed fields “server”, “message”, “client”. I was unable to see this parsed fields in graylog but see they in “stdout { codec => rubydebug }” output.
Once i have rename these fields to “server1”, “message1”, “client1” they appeared in graylog. Is they like “reserver” fields? If yes why it is denied to name custom values like reserver? And where can find full list of reserver fields?
Thank you.
jochen
(Jochen)
August 21, 2017, 1:58pm
2
“message” is kind of a reserved field. The other two fields (“server” and “client”) should have shown up.
mpolitaev
(Mihail Politaev)
August 21, 2017, 6:19pm
3
Thank you jochen,
How i can get all reserved field list? For what purpose reserved fields is?
jochen
(Jochen)
August 22, 2017, 6:48am
4
private static final ImmutableSet<String> GRAYLOG_FIELDS = ImmutableSet.of(
"gl2_source_node",
"gl2_source_input",
// TODO Due to be removed in Graylog 3.x
"gl2_source_radio",
"gl2_source_radio_input",
"gl2_source_collector",
"gl2_source_collector_input",
"gl2_remote_ip",
"gl2_remote_port",
"gl2_remote_hostname"
);
private static final ImmutableSet<String> CORE_MESSAGE_FIELDS = ImmutableSet.of(
FIELD_MESSAGE,
FIELD_SOURCE,
FIELD_TIMESTAMP
);
This file has been truncated. show original
The reserved fields are being used for various functions in Graylog, for example “message” is the default message shown in the web interface.
mpolitaev
(Mihail Politaev)
August 22, 2017, 7:45am
5
Thank you jochen.
I thought internal graylog-template has reserved fields and custom user fields. For which then is graylog-template in elasticsearch?
jochen
(Jochen)
August 22, 2017, 9:17am
6
The index template is required so that certain fields in Elasticsearch have a defined type (instead of being “auto-detected” by Elasticsearch).
See http://docs.graylog.org/en/2.3/pages/configuration/elasticsearch.html#custom-index-mappings for details.
system
(system)
Closed
September 5, 2017, 12:11pm
8
This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.