Hi,
I have created eventLogTime field in logstash indexer and assign timestamp form the log. I have provided list of timestamp while doing this. Now the problem is when we are adding applications in centralized logging, some systems have timestamps which are not in the list provided in indexer.
Then it gives error (grokeparsefailure). Due to this I have decided to remove this filter, as its of less importance.
After commenting out this filer, I can still see eventLogTime field for new logs on Kibana?
I hope it should not be there for new logs.
Hi,
But I think this will work for current documents which are getting stored.
It saying evenLogTIme is conflicting across indexes. How to solve this? How to get those indexes in which eventLogTime field has conflicting data type?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.