im new logstash , created config file processing 2 different kind of file. i've created field similar in fields same in input file , have correlate of value request response. while in scenario im facing following error, in query section im parsing datat similar though why shown error im in clueless.im storing both file in same index. if run file without deleting index mean correlate.
my correlation : " elasticsearch { sort => [ { "partorder.orderrefno" => {"order" => "asc" "ignore_unmapped" => true} "dlr.dlrcode" => {"order" => "asc" "ignore_unmapped" => true} } ] query => "type:transmit_req , partorder.orderrefno : %{partorder.orderrefno} , dlr.dlrcode : %{dlr.dlrcode}" fields => [ "partorder.totallineno", "partorder.totallineno", "partorder.totalorderqty", "partorder.totalorderqty", "partorder.transportmethodtype","partorder.transportmethodtype", "dlr.brand","dlr.brand", "partorder.ordertype","partorder.ordertype", "partorder.bodid","partorder.bodid" ] fail_on_error => "false" } " error: " ←[33mfailed query elasticsearch previous event {:query=>"type:transmit_re q , partorder.orderrefno : bc728010 , dlr.dlrcode : 28012", :event=># , @metrics={}, @channel=#>, @subscriber_lock=#, @level=:warn, @subscribers={2002=>#