Two record formats that start a multiline event, what grok statement might I use to keep the milliseconds and set the time as the @timestamp field? Maybe I have to drop the milliseconds?
Thank you
23:29:53.425: Sending [0,UDP] 467 bytes to 10.80.131.7:5060 >>>>>
@23:29:53.425: Sending [0,UDP] 467 bytes to 10.80.131.7:5060 >>>>>
I have been all over the map trying different regex and grok ideas:
^(@)?(?[^:]):(?[^:]):(?[^.]*)
(?!<[0-9])%{HOUR}:%{MINUTE}(?::%{SECOND})(?![0-9])
TIMESTAMP_ISO8601
etc