Could you please advise how to assign specific log files (with specific naming convention) to a specific stream. I’ve tried using pipeline and rules like below but didn’t work:
// we use only one rule to identify if this is an GetsubProf log file
// in all following rules it is possible to check just this single field.
// following rules can just check for:
// put any identifier you have for the GetsubProf log file
// in this rule
to_string($message.facility) == “filebeat” AND
// the following rule only work if the GetsubProf log file is
// in the default location
to_string($message.file) == “/var/log/log_analytics/GetsubProf sample116.log” AND
// you need to adjust that if you change the field in the collector configuration!
Thanks and thanks in advance,