Hi i am very new to the elk stack. I have a log file that shows the date and time of when a file was processed but when I send it off to elasticsearch the timestamp field that shows up is the current date and time. How do I have to configure the logstash config file so that instead of having the real time timestamp I can have the timestamp of the log file?
the way I am processing this log is: filebeat > logstash > elasticsearch > kibana
this is an example of the data in the log file:
10.01.17 18:24:02.85 SchLd: Added schedule record: Count J[CD 0111]EffDt[17 Oct 31]Freq[.2.....]DscDt[17 Oct 31]ImplDt[17 Jul 25]
I want the time stamp to be replaced with the first part "10.01.17 18:24:02.85"
here is my config file :
port => "5043"
hosts => [ "localhost:9200" ]
I really appreciate your guy's help!