Check if your log format (or application) that you are parsing is one of our supported modules,
If you are sending your events directly to Elasticsearch,
If you send your events through Logstash,
I'm not using Logstash. Does it have any advantages for this task?
You may want to look at these processors: grok and date, You will also need to configure the filebeat output to send to the correct pipeline.
I tried date earlier, when I was using only one prospector for "YYYYMMDD-hhmmss" format. For some reason it didn't work, and I reverted to defaults. What changes do I need to make to the example here https://www.elastic.co/guide/en/elasticsearch/reference/current/date-processor.html ? Would it be enough to change the "formats" line to
"formats" : ["YYYYMMDD-hhmmss"], ?
P.S. Note to self: Joda format specification says it should be "yyyyMMdd-HHmmss".