Hello, when catching up source at props.conf stanza you have to use two colons instead of equal sign. Like [source::http:docker] For regex I would use capturing group, for example REGEX = security_level\":\"([^"]*) DEST_KEY = _MetaData:Index FORMAT = $1 When event goes to xx -index. Or as hard coded REGEX = security_level\":\"xx\" DEST_KEY = _MetaData:Index FORMAT = xx_index Event ends up to xx_index -index.
... View more