Please see the below where I am wrinting the filter grep and record_transformation in my td-agent config file, But I am not getting mutate fields and rename fields in kibana.
<filter syslog>
@type grep
regexp1 message SYSLOG5424LINE
regexp2 SYSLOG5424 SYSLOGLINE
regexp3 prival prival
regexp4 timestamp timpstamp
regexp5 host hostname
</filter>
<filter syslog>
@type record_transformer
enable_ruby
mutate
remove_message,remove_host #remove fields.
<record>
add_tag ${syslog5424}
</record>
</filter>
<filter syslog>
@type record_transformer
enable_ruby
mutate
remove_syslog5424_ver,remove_syslog5424_proc #remove fields.
renew_record true
<record>
syslog5424_app ${syslog5424_app.to_s}
add_tag ${services}
syslog5424_msg ${syslog5424_msg.to_s}
add_tag ${message}
syslog5424_host ${syslog5424_host.to_s}
add_tag ${host}
</record>
</filter>
Please assist me to write custome filter in correct way for syslog5424.
Regards:
Parima Soni