Open icetimidus opened 4 years ago
this isn't supported atm, and I am not sure it ever will be. the current work-flow is load the pattern definitions once (for performance reasons) before any events are matched.
the closest one could do is having separate grok plugin instances if-ed based on event data e.g.
filter {
if [some_field] {
grok {
pattern_definitions => {
"SOME_PATTERN" => '...'
}
}
}
}
May I using logstash evnet fileds in grok filter configuration options?
Such as,
or
I have try it in logstash 7.6.1 but faild. Any idea?