Hello @stephenb, thanks for your feedback.
Here is the mapping file:
{"test_log":
{"aliases":{},
"mappings":{
"properties":{
"@timestamp":{"type":"date"},
"@version":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},
"host":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},
"loglevel":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},
"message":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},
"msg":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},
"path":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},
"my_timestamp":{"type":"date","ignore_malformed":true},
"user":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}}
}
},
"settings":{
"index":{
"creation_date":"1689673689010",
"number_of_shards":"1",
"number_of_replicas":"1",
"uuid":"f5a8C8654asfcrFFEfvc5f",
"version":{"created":"7010199"},
"provided_name":"test_log"
}
}
}
}
Sample docs:
{
"took" : 23,
"timed_out" : false,
"_shards" : {
"total" : 1,
"successful" : 1,
"skipped" : 0,
"failed" : 0
},
"hits" : {
"total" : {
"value" : 10000,
"relation" : "gte"
},
"max_score" : 1.0,
"hits" : [
{
"_index" : "test_log",
"_type" : "_doc",
"_id" : "gbeb8zdfefb7eefv57efef7",
"_score" : 1.0,
"_ignored" : [
"my_timestamp"
],
"_source" : {
"@version" : "1",
"msg" : "ERROR: Some error message",
"loglevel" : "ERROR",
"user" : "0123456789101112",
"host" : "my_ip_adress",
"@timestamp" : "2023-07-18T09:50:47.453Z",
"path" : "/home/sas_log_file.log",
"message" : "2023-07-15T07:32:01,645 ERROR [00000870] :0123456789101112 - ERROR: Some error message",
"my_timestamp" : "2023-07-15T07:32:01,645"
},
"fields" : {
"msg" : [
"ERROR: Some error message"
],
"loglevel.keyword" : [
"ERROR"
],
"@version.keyword" : [
"1"
],
"message" : [
"2023-07-15T07:32:01,645 ERROR [00000870] :0123456789101112 - ERROR: Some error message"
],
"user.keyword" : [
"0123456789101112"
],
"msg.keyword" : [
"ERROR: Some error message"
],
"my_timestamp" : [
"2023-07-15T07:32:01,645Z"
],
"path" : [
"/home/sas_log_file.log"
],
"@timestamp" : [
"2023-07-18T09:50:47.453Z"
],
"loglevel" : [
"ERROR"
],
"message.keyword" : [
"2023-07-15T07:32:01,645 ERROR [00000870] :0123456789101112 - ERROR: Some error message"
],
"@version" : [
"1"
],
"host" : [
"my_ip_adress"
],
"host.keyword" : [
"my_ip_adress"
],
"user" : [
"0123456789101112"
],
"path.keyword" : [
"/home/sas_log_file.log"
]
}
},
{
"_index" : "test_log",
"_type" : "_doc",
"_id" : "gk4zdfzE7eR55fdfzef7",
"_score" : 1.0,
"_ignored" : [
"my_timestamp"
],
"_source" : {
"@version" : "1",
"msg" : "1 Some INFO message",
"loglevel" : "INFO",
"user" : "0123456789101112",
"host" : "my_ip_adress",
"@timestamp" : "2023-07-18T09:50:47.499Z",
"path" : "/home/sas_log_file.log",
"message" : "2023-07-15T07:32:01,648 INFO [00000870] :0123456789101112 - 1 Some INFO message",
"my_timestamp" : "2023-07-15T07:32:01,648"
},
"fields" : {
"msg" : [
"1 Some INFO message"
],
"loglevel.keyword" : [
"INFO"
],
"@version.keyword" : [
"1"
],
"message" : [
"2023-07-15T07:32:01,648 INFO [00000870] :0123456789101112 - 1 Some INFO message"
],
"user.keyword" : [
"0123456789101112"
],
"msg.keyword" : [
"1 Some INFO message"
],
"my_timestamp" : [
"2023-07-15T07:32:01,648Z"
],
"path" : [
"/home/sas_log_file.log"
],
"@timestamp" : [
"2023-07-18T09:50:47.499Z"
],
"loglevel" : [
"INFO"
],
"message.keyword" : [
"2023-07-15T07:32:01,648 INFO [00000870] :0123456789101112 - 1 Some INFO message"
],
"@version" : [
"1"
],
"host" : [
"my_ip_adress"
],
"host.keyword" : [
"my_ip_adress"
],
"user" : [
"0123456789101112"
],
"path.keyword" : [
"/home/sas_log_file.log"
]
}
}
]
}
}
Screen of the index pattern (Only date fields):
Hope those elements can be helpful !