Hello My log file looks like:
[
{
"textPayload": "{'testkey': 'testvalue'}",
"insertId": "12345-12345",
"resource": {
"type": "cloud_function",
"labels": {
"project_id": "project-p123",
"region": "us-east4",
"function_name": "testfunction"
}
},
"timestamp": "2021-11-16T16:07:56.647Z",
"severity": "INFO",
"labels": {
"execution_id": "uji09345"
},
"logName": "projects/project-p123/logs/cloudfunctions",
"trace": "projects/project-p123/traces/uhne1234",
"receiveTimestamp": "2021-11-16T16:08:06.721583231Z"
}
]
And my filter looks like:
filter {
date {
match => ["timestamp", "ISO8601"]
target => ["@timestamp"]
remove_field => ["timestamp"]
}
date {
match => ["receiveTimestamp", "ISO8601"]
target => ["receiveTimestamp"]
#remove_field => ["receiveTimestamp"]
}
}
All the other fields are coming in perfectly fine except the timestamps.
Please help in fixing this issue.
Thank you.