Add a key/value pair with key KEY and value VALUE. If KEY already exists, this field is overwritten
Add
STRING:KEY
STRING:VALUE
Add a key/value pair with key KEY and value VALUE if KEY does not exist
Remove
STRING:KEY
NONE
Remove a key/value pair with key KEY if it exists
Remove_wildcard
WILDCARD:KEY
NONE
Remove all key/value pairs with key matching wildcard KEY
Remove_regex
REGEXP:KEY
NONE
Remove all key/value pairs with key matching regexp KEY
Rename
STRING:KEY
STRING:RENAMED_KEY
Rename a key/value pair with key KEY to RENAMED_KEY if KEY exists AND RENAMED_KEYdoes not exist
Hard_rename
STRING:KEY
STRING:RENAMED_KEY
Rename a key/value pair with key KEY to RENAMED_KEY if KEY exists. If RENAMED_KEY already exists, this field is overwritten
Copy
STRING:KEY
STRING:COPIED_KEY
Copy a key/value pair with key KEY to COPIED_KEY if KEY exists AND COPIED_KEYdoes not exist
Hard_copy
STRING:KEY
STRING:COPIED_KEY
Copy a key/value pair with key KEY to COPIED_KEY if KEY exists. If COPIED_KEY already exists, this field is overwritten
Rules are case insensitive, parameters are not
Any number of rules can be set in a filter instance.
Rules are applied in the order they appear, with each rule operating on the result of the previous rule.
Conditions
The plugin supports the following conditions:
Condition
Parameter
Parameter 2
Description
Key_exists
STRING:KEY
NONE
Is true if KEY exists
Key_does_not_exist
STRING:KEY
STRING:VALUE
Is true if KEY does not exist
A_key_matches
REGEXP:KEY
NONE
Is true if a key matches regex KEY
No_key_matches
REGEXP:KEY
NONE
Is true if no key matches regex KEY
Key_value_equals
STRING:KEY
STRING:VALUE
Is true if KEY exists and its value is VALUE
Key_value_does_not_equal
STRING:KEY
STRING:VALUE
Is true if KEY exists and its value is not VALUE
Key_value_matches
STRING:KEY
REGEXP:VALUE
Is true if key KEY exists and its value matches VALUE
Key_value_does_not_match
STRING:KEY
REGEXP:VALUE
Is true if key KEY exists and its value does not match VALUE
Matching_keys_have_matching_values
REGEXP:KEY
REGEXP:VALUE
Is true if all keys matching KEY have values that match VALUE
Matching_keys_do_not_have_matching_values
REGEXP:KEY
REGEXP:VALUE
Is true if all keys matching KEY have values that do not match VALUE
Conditions are case insensitive, parameters are not
Any number of conditions can be set.
Conditions apply to the whole filter instance and all its rules. Not to individual rules.
All conditions have to be true for the rules to be applied.
Example #1 - Add and Rename
In order to start filtering records, you can run the filter from the command line or through the configuration file. The following invokes the Memory Usage Input Plugin, which outputs the following (example),
[INPUT] Name mem Tag mem.local[OUTPUT] Name stdout Match *[FILTER] Name modify Match * Add Service1 SOMEVALUE Add Service3 SOMEVALUE3 Add Mem.total2 TOTALMEM2 Rename Mem.free MEMFREE Rename Mem.used MEMUSED Rename Swap.total SWAPTOTAL Add Mem.total TOTALMEM
Result
The output of both the command line and configuration invocations should be identical and result in the following output.
[INPUT] Name mem Tag mem.local Interval_Sec 1[FILTER] Name modify Match mem.* Condition Key_Does_Not_Exist cpustats Condition Key_Exists Mem.used Set cpustats UNKNOWN[FILTER] Name modify Match mem.* Condition Key_Value_Does_Not_Equal cpustats KNOWN Add sourcetype memstats[FILTER] Name modify Match mem.* Condition Key_Value_Equals cpustats UNKNOWN Remove_wildcard Mem Remove_wildcard Swap Add cpustats_more STILL_UNKNOWN[OUTPUT] Name stdout Match *
[INPUT] Name mem Tag mem.local[OUTPUT] Name stdout Match *[FILTER] Name modify Match * Remove_Wildcard Mem Remove_Wildcard Swap Set This_plugin_is_on 🔥 Set 🔥 is_hot Copy 🔥 💦 Rename 💦 ❄️ Set ❄️ is_cold Set 💦 is_wet