Grok GUnicorn error log date format?

If it works it is OK. That said, personally I would use a dissect filter for a delimited format like that

dissect { mapping => { "message" => "[%{thetime}] [%{pid}] [%{level}] %{event}" } }
1 Like