Class GrokProcessor
java.lang.Object
co.elastic.clients.elasticsearch.ingest.ProcessorBase
co.elastic.clients.elasticsearch.ingest.GrokProcessor
- All Implemented Interfaces:
ProcessorVariant,JsonpSerializable
- See Also:
-
Nested Class Summary
Nested ClassesNested classes/interfaces inherited from class co.elastic.clients.elasticsearch.ingest.ProcessorBase
ProcessorBase.AbstractBuilder<BuilderT extends ProcessorBase.AbstractBuilder<BuilderT>> -
Field Summary
FieldsModifier and TypeFieldDescriptionstatic final JsonpDeserializer<GrokProcessor>Json deserializer forGrokProcessor -
Method Summary
Modifier and TypeMethodDescriptionProcessor variant kind.final StringMust be disabled or v1.final Stringfield()Required - The field to use for grok expression parsing.final BooleanIftrueandfielddoes not exist or isnull, the processor quietly exits without modifying the document.static GrokProcessorA map of pattern-name and pattern tuples defining custom patterns to be used by the current processor.patterns()Required - An ordered list of grok expression to match and extract named captures with.rebuild()protected voidserializeInternal(jakarta.json.stream.JsonGenerator generator, JsonpMapper mapper) protected static voidfinal BooleanWhentrue,_ingest._grok_match_indexwill be inserted into your matched document’s metadata with the index into the pattern found inpatternsthat matched.final BooleanWhentrue, the processor does matching but does not extract structured fieldsMethods inherited from class co.elastic.clients.elasticsearch.ingest.ProcessorBase
description, if_, ignoreFailure, onFailure, serialize, setupProcessorBaseDeserializer, tag, toStringMethods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, wait, wait, waitMethods inherited from interface co.elastic.clients.elasticsearch.ingest.ProcessorVariant
_toProcessor
-
Field Details
-
_DESERIALIZER
Json deserializer forGrokProcessor
-
-
Method Details
-
of
-
_processorKind
Processor variant kind.- Specified by:
_processorKindin interfaceProcessorVariant
-
ecsCompatibility
Must be disabled or v1. If v1, the processor uses patterns with Elastic Common Schema (ECS) field names.API name:
ecs_compatibility -
field
Required - The field to use for grok expression parsing.API name:
field -
ignoreMissing
Iftrueandfielddoes not exist or isnull, the processor quietly exits without modifying the document.API name:
ignore_missing -
patternDefinitions
A map of pattern-name and pattern tuples defining custom patterns to be used by the current processor. Patterns matching existing names will override the pre-existing definition.API name:
pattern_definitions -
patterns
Required - An ordered list of grok expression to match and extract named captures with. Returns on the first expression in the list that matches.API name:
patterns -
traceMatch
Whentrue,_ingest._grok_match_indexwill be inserted into your matched document’s metadata with the index into the pattern found inpatternsthat matched.API name:
trace_match -
validateOnly
Whentrue, the processor does matching but does not extract structured fieldsAPI name:
validate_only -
serializeInternal
- Overrides:
serializeInternalin classProcessorBase
-
rebuild
- Returns:
- New
GrokProcessor.Builderinitialized with field values of this instance
-
setupGrokProcessorDeserializer
-