Dateadd feature in logstash


We have some log files which is dynamic in pattern. We would like to filter the logdate field as, whenver the value is null, then that value should be equal to current timestamp less 6hrs.

In sql, its the same as


I would like to know how can i accomplish this.

Nver mind. The workaround we did is to use ruby filter. See below.

	ruby {
			init => "require 'time'"
		code => "event.set('logdate', - 6*60*60);"

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.