Hi,
This is how my event logs looks like : <<ERROR>> [Jul 25 19:17:08] [[ACTIVE]
I am trying to filter the time stamp.
The grok looks like: \<\<%{LOGLEVEL:severity}\>\> \[%{PARTTIMESTAMP:timestamp}\] \[\[%{DATA}\]
And we added the following filter:
date {
match => [ "timestamp" , "MMM dd hh:mm:ss"]
}
In the Kibana, we keep getting _dateparsefailure
Can you pls help to understand what is wrong?
Thanks
Sharon.