Am not able to filter the following date through grok, it doesnt fall under any ready made TIMESTAMP filters:
07 Aug 2019 13:54:27.463
I want to retrive it and replace it with @timestamp (or create a "Date" variable and add it there)
Thanks
Am not able to filter the following date through grok, it doesnt fall under any ready made TIMESTAMP filters:
07 Aug 2019 13:54:27.463
I want to retrive it and replace it with @timestamp (or create a "Date" variable and add it there)
Thanks
Hi,
You can use the Date Filter to create arbitrary (and multiple) patterns for handling date/time stamps.
@ben.west I know about the Date Filter but am not able to find the right syntax to fit with my need. Can you please advise?
This should work: dd MMM yyyy HH:mm:ss.SSS
how would the whole config be in this case? like this?
date {
match => [ "Date", "dd MMM yyyy HH:mm:ss.SSS" ]
target => "Date"
}
Yes that should work. You mentioned in your original post you wanted to update the @timestamp
field of the event so you can omit the target to do this automatically.
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.