I have logs that are spitting out in the following format:
[2018-06-24 07:00:03 -0700] DEBUG - CrewManagement::API - backbone:sync_tokens - {\"description\":\"Sync local tokens with Backbone-Auth - 114\",\"success\":true}
I have messed around with the Grok Debugger, and I can extract everything except the -0700
part. I need to extract the Timestamp and convert it into a UTC date for kibana to see
I'm currently stuck on
%{TIMESTAMP_ISO8601:event_timestamp} %{DATA:timezone}
# -------- which computes to the following --------
{
"event_timestamp": [
["2018-06-24 07:00:03"]
],
"YEAR": [
["2018"]
],
"MONTHNUM": [
["06"]
],
"MONTHDAY": [
["24"]
],
"HOUR": [
[ "07", null]
],
"MINUTE": [
["00", null]
],
"SECOND": [
["03"]
],
"ISO8601_TIMEZONE": [
[null]
],
"timezone": [
[""]
]
}