Hi, I am trying to drop the 4 miliseconds from the timestamp but i cannot make it work and it's given me an error of _dateparsefailure
the bit where I have the error is:
grok {
match => [ "message", "%{TIMESTAMP_ISO8601:fechalog} %{LOGLEVEL:Severity} %{GREEDYDATA:Message}" ]
}
mutate {
gsub => ["fechalog", "\.\d{4}$"]
}
date {
match => ["fechalog", "YYYY-MM-dd HH:mm:ss" ]
timezone => "UTC"
}
mutate {
add_field => { "Ubicacion" => "%{[host][hostname]}-%{[log][file][path]}"}
}
mutate {
remove_tag => ["beats_input_codec_plain_applied"]
}
an example log...
2020-05-09 22:34:05.0880 ERROR DatosGruas.BOL.Trama.Leer
I can see that the fechalog
field its been filled with the right timestamp. I guess my mutate is not right and that is making fail my date filter???
Thanks in advance