I have a problem, the netflow filebeat module keep the timestamp of inside the netflow packet. Here 1993-12-03..., but I want modify this value by the current time.
So currently Filebeat reads the date on the Netflow/IPFIX header and uses that as @timestamp field, there's no configuration flag to use the current ingestion time instead.
However you can work around it with the script processor:
Consider adding a whencondition so that it only applies to Netflow events.
About the wrong date, is the date set wrong on your netflow device or Filebeat is parsing it incorrectly? If you're unsure, can you share a pcap with the netflow traffic?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.