-
Notifications
You must be signed in to change notification settings - Fork 310
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Specify template for elasticsearch to get . notation working #179
Labels
Comments
Is your field |
Hello, it is tag:
|
right, so mapping should be |
same for other fields, except for |
I checked server and this is current mapping. No success. |
Don't know how else to help here, it seems that logs are indexed properly. |
No response and seems to be working properly. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Hello I have been trying to resolve problem as specified in #33.
The problem is:
I have tags which consist from "." separated fields and i want to be able to filter messages according to this field.
More specifically I have these tags:
host1.server.sender
host1.server.receiver
host2...
What I want to achieve is to be able to search for host1.server.* or host1.* or *.server (wildcard search)
My solution was to put template into elasticsearch as follows:
When checking index pattern in Kibana i see that tag field and others are correctly unchecked -> not_analyzed.
Searching for tag:"application.*.server" (simplified) returns no results. I am not entirely sure whether my template is wrong or whether something else is wrong
The text was updated successfully, but these errors were encountered: