How to filter a time stamp with no year value


(Sharon Sasporta) #1

Hi,

This is how my event logs looks like : <<ERROR>> [Jul 25 19:17:08] [[ACTIVE]

I am trying to filter the time stamp.

The grok looks like: \<\<%{LOGLEVEL:severity}\>\> \[%{PARTTIMESTAMP:timestamp}\] \[\[%{DATA}\]

And we added the following filter:

date {
                      match => [ "timestamp" , "MMM dd hh:mm:ss"]
        }

In the Kibana, we keep getting _dateparsefailure

Can you pls help to understand what is wrong?

Thanks
Sharon.


(Sharon Sasporta) #2

solved.

hh doesn't exist.

HH sloved the issues.


(Magnus B├Ąck) #3

hh does exist but is for 12-hour times.


(system) #4

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.