How to filter a time stamp with no year value


This is how my event logs looks like : <<ERROR>> [Jul 25 19:17:08] [[ACTIVE]

I am trying to filter the time stamp.

The grok looks like: \<\<%{LOGLEVEL:severity}\>\> \[%{PARTTIMESTAMP:timestamp}\] \[\[%{DATA}\]

And we added the following filter:

date {
                      match => [ "timestamp" , "MMM dd hh:mm:ss"]

In the Kibana, we keep getting _dateparsefailure

Can you pls help to understand what is wrong?



hh doesn't exist.

HH sloved the issues.

hh does exist but is for 12-hour times.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.