elastic / elastic/logstash

Create 'exec' filter

Open
#2,528 1 comment 1 reaction 0 assignees View on GitHub
help wanted new plugin
Dominant language
Java
Stars
14.9k
Forks
3.5k
Avg merge
19h 14m
Merged PRs (30d)
63

Description

Migrated from https://logstash.jira.com/browse/LOGSTASH-119:

> Would be useful to pipe arbitrary fields through a command to modify them.
>
> Here's an example that would anonymize hostnames or something.
>
> ```
> filter {
> exec {
> command => "sed -re 's/\S+\.loggly\.com/anonymizedhost.example.com/'"
> fields => [ "@message", "hostname", "@source_host" ]
> }
> }
> ```
>
> The default would use only the `message` to parse
>
> The protocol between logstash and the exec filter must be strict. Something like:
> for every line emitted, one line must be emitted as the 'new' line. If no changes are made, simply print it unmodified.
>
> deleting the field can be done by printing a blank line
>
> we exec the process once and use stdin for sending data, stdout for reading responses; if it dies, some retries should occur

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.