I'm trying to parse 180711T221704.507399z into @timestamp with
date { match => ["log_time","yyMMddHHmmss.SSSSSS"] }
but keep getting "dateparsefailure".
I've tried "ISO8601", adding the T, z, and a everything short of breaking it up. Appreciate suggestions.
Have you tried yyMMddHHmmss.SSSSSS'z' (yes, with single quotes around the "z")?
yyMMddHHmmss.SSSSSS'z'
yup. same result
date { match => [ "message", "yyMMdd'T'HHmmss.SSSSSS'z'" ] }
works for me.
giddeeup! yes this works.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.