Is the grok expression working so that the field is actually extracted? If you look at the data in Elasticsearch, do you see a _grokparsefailure tag? If not, can you show us what anindexed document looks like?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.