Grok patter to remove trailing milliseconds

Two record formats that start a multiline event, what grok statement might I use to keep the milliseconds and set the time as the @timestamp field? Maybe I have to drop the milliseconds?

Thank you

23:29:53.425: Sending [0,UDP] 467 bytes to >>>>>
@23:29:53.425: Sending [0,UDP] 467 bytes to >>>>>

I have been all over the map trying different regex and grok ideas:

Where are you using those grok patterns (Logstash)? Because we've got a nice channel for that :slight_smile:

In kabana.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.