How to write grok match for following date in logstash:

I have tried following but it is giving "_dateparsefailure:"

match => [ "timestamp" , "yyyyMMddHHmmss.SSSZ" ]

Any help please!!!

your format has T in the middle, so you need this instead:

filter { date { match => [ "message" , "yyyyMMdd'T'HHmmss.SSSZ" ] } }

Sry for the delayed reply, this pattern worked :slight_smile:

Thanks alot !!

1 Like

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.