Hello. We are getting feed from Kafka topic. One of the fields rdt
appears in the following format:
I need to change the date format to YYYY-MM-dd
This was added in the logstash conf file:
if "KafkCollect" in [tags] {
file {
path => "/opt/total/logs/kafkaCollect_rubydebug.txt"
codec => rubydebug
}
filter {
mutate {
strip => ["rdt"]
}
date {
match => ["rdt", "YYYY-MM-dd"]
target => "rdt"
}
}
elasticsearch {
hosts => [ "xxx.xx.xx.xx:43045" ]
hosts => [ "xxx.xx.xx.xx:43045" ]
hosts => [ "xxx.xx.xx.xx:43045" ]
hosts => [ "xxx.xx.xx.xx:43045" ]
user => "datater"
password => "xxxxxxxxxx"
index => "dateter-coll-%{+YYYY.MM.dd}"
manage_template => true
template_overwrite => true
template => "/opt/total/logstash/config/data_kafkaCollect_template.json"
template_name => "dataCollect_template"
}
}
This gives syntax error at startup.
Please guide
Thanks