Hello I hope can you help me
For example I have this event in log:
18-05-30;15:38:06.282 \hola.1,237 aaaaaa bbb
ccccccc ddd
With configuration below index only events that cointain ddd in log
props.conf
[tef]
TRANSFORMS-set= setnull,setparsing
transforms.conf
[setnull]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue
[setparsing]
REGEX = ddd
DEST_KEY = queue
FORMAT = indexQueue
But I don't want index event complete, only "ddd"
Thank you in advance
if your event parsing is correct, I think you just need to reverse order in the props - transforms-set. First Match and send to indexqueue, then everything else to nullqueue
TRANSFORMS-set= setparsing,setnull