How to overwrite the @timestamp with the value in the log?


(Prateeksha Shetty) #1

There is NO logstash in the picture. We are using filebeat to directly push logs to Kibana.


(ruflin) #2

I think you are looking for the ingest node feature in Elasticsearch: https://www.elastic.co/guide/en/elasticsearch/reference/6.3/ingest.html


(Prateeksha Shetty) #3

I'm very new to ELK and I don't understand how ingest node can be used here. Can you please elaborate?


(ruflin) #4

I assume most likely you are looking for the grok processor: https://www.elastic.co/guide/en/elasticsearch/reference/6.3/grok-processor.html


(system) #5

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.