Hello !
I have the field "Generated Time" in my message. I want to use it as primary date field in Kibana.
To do so, I create my index pattern and choose "Generated Time" as primary date field. But once in Discover, nothing is displayed. Like if Kibana don't understand this field.
GET myindex/_search :
{
"took" : 0,
"timed_out" : false,
"_shards" : {
"total" : 1,
"successful" : 1,
"skipped" : 0,
"failed" : 0
},
"hits" : {
"total" : {
"value" : 1,
"relation" : "eq"
},
"max_score" : 1.0,
"hits" : [
{
"_index" : "palo",
"_type" : "_doc",
"_id" : "lZdviXkBTGy11OBhDMD8",
"_score" : 1.0,
"_source" : {
"@timestamp" : "2021-05-20T11:00:30.917Z",
"Receive Time" : "2021/05/20 14:06:46",
"Packets Received" : "1",
"Session ID" : "1299262",
"Destination Port" : "53",
"Destination VM UUID" : null,
"Generated Time" : "2021/05/20 14:06:46",
"NAT Destination IP" : "0.0.0.0",
"Monitor Tag/IMEI" : null,
"SCTP Chunks Sent" : "0",
"syslog_timestamp" : "May 20 14:06:47",
"Device Group Hierarchy Level 1" : "1829",
"NAT Destination Port" : "0"
}
}
]
}
}
mapping :
"Generated Time" : {
"type" : "date",
"format" : "yyyy/MM/dd HH:mm:ss||yyyy/MM/dd||epoch_millis"
},
If I choose @timestamp as primary date field, it works. I can see the log.
Thanks for your help !