Also, you probably want to remove_field => ["logtime"] in your date filter, since timestamp isn't a field that exists in your grok pattern.
Also, you probably want to remove_field => ["logtime"] in your date filter, since timestamp isn't a field that exists in your grok pattern.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.