How to overwrite the @timestamp with the value in the log?

(Prateeksha Shetty) #1

There is NO logstash in the picture. We are using filebeat to directly push logs to Kibana.

(ruflin) #2

I think you are looking for the ingest node feature in Elasticsearch:

(Prateeksha Shetty) #3

I'm very new to ELK and I don't understand how ingest node can be used here. Can you please elaborate?

(ruflin) #4

I assume most likely you are looking for the grok processor:

(system) #5

