RFE: Add config option to skip the event.cancel at the end of the filter flow
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 35/100
Research direction
The issue names no files or tests. Start by locating the split filter entry point and the handling of event.cancel, then reproduce the three sequential split calls with keep_original enabled. Done means the requested configuration option supports repeated splits while preserving existing behavior by default.
Written by the indexing model from the issue text.
Description
I'm using the split filter along with the logstash-input-snmp to gather SNMP data and ingest into Elastic.
In order to ingest data on a per-core, per-interface, per-filesystem basis, I'm using separate input blocks with tagging and then using the split filter based on the tags.
What I'd like to be able to do is use a single snmp input to walk a device and then use the split filter on the original event multiple times to split out the various tables of data.
e.g. Based on a rough format of:
"device_name": "mydevice.my.domain",
"device_version": "1.2.3.4",
"device_uptime": 123456,
"cpu": {
1 => "data",
2 => "data",
3 => "data"
},
"mem": {
1 => "data",
2 => "data",
3 => "data"
},
"int": {
1 => "data",
2 => "data",
3 => "data"
}
I could use a pipeline with:
if "cpu_split" in [tags] {
#do cpu related parsing and cleanup (drop non cpu fields)
} else if "mem_split" in [tags] {
#do mem related parsing and cleanup (drop non mem fields)
} else if "int_split" in [tags] {
#do int related parsing and cleanup (drop non int fields)
} else {
split {
field => "cpu"
keep_original => true
add_tag => [ "cpu_split" ]
}
split {
field => "mem"
keep_original => true
add_tag => [ "mem_split" ]
}
split {
field => "int"
keep_original => true
add_tag => [ "int_split" ]
}
# Drop cpu/mem/int fields and parse the rest of results (or just drop{} if nothing left)
}
- Dominant language
- Ruby
- Stars
- 6
- Forks
- 29
- PR merge metrics
- No merged PRs in 30d
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from logstash-plugins/logstash-filter-split
-
enhancement status:needs-triage
Difficulty 5/5 Over a week Newbie friendliness 35/100
-
enhancement
Difficulty 5/5 Over a week Newbie friendliness 25/100
-
bug
Difficulty 3/5 1-2 days Newbie friendliness 45/100
logstash-plugins/logstash-filter-split#47 · 1 comment · 1 reaction ·
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
logstash-plugins/logstash-filter-split#42 · 1 comment ·
-
Split Filter is not multi thread, how to fix this?May be free again @colinsurprenant claimed this 2785 days ago, and no pull request is open. Open
logstash-plugins/logstash-filter-split#37 · 1 comment · 1 assignee ·
All issues in logstash-plugins/logstash-filter-split
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
FreeCAD/homebrew-freecad#870 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
security
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day
-
OSCON 2016Opencontent
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
rubyevents/rubyevents#2148 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
we-promise/sure#3838 · 2 comments ·
Maintainers usually reply within 1 day