I would use
ruby { code => '@@metadata = event.get("@timestamp")' }
for the snapshot lines, and
ruby { code => 'event.set("@timestamp", @@metadata)' }
for the others.
I would use
ruby { code => '@@metadata = event.get("@timestamp")' }
for the snapshot lines, and
ruby { code => 'event.set("@timestamp", @@metadata)' }
for the others.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.