The problem i have is that the logdate field comes through to Kibana as a string so i cannot apply between filters to this field.
I read that this is expected behaviour, but i can't find an easy answer to solve the problem i have.
I would also like to flip the fields so the "@timestamp" field contains the current logdate information - is that as easy as changing the grok to (%{TIMESTAMP_ISO8601:@timestamp}) ?
I was hoping that, following this change, when i created a new index pattern, i'd have the option of using "logdate" as the time field, but it isn't showing in the list and, if i proceed to create the index pattern on @timestamp then logdate still shows as a String in the field list on the next page.
I can see its made a change to the output in Discover view now as the Logdate is now showing slightly differently to the Original Input:
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.