Skip to content

Expanding a log Message to 2 #10286

Discussion options

You must be logged in to vote

This example should help, and there is also an unnest function to help here as well.

It looks like your example log is more or less the same pattern as the example and something like . = parse_json!(.alerts) would work (with some additional work if you wanted to retain original fields).

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by jszwedko
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants