At the top you can see an example of TimeStamp and below is how I would go about parsing it. I would like to however on parse the hour of the day into the new field HourOfDay and then keep the TimeStamp field as is.
Hi @magnusbaeck I tried changing my config to the above and restarted Logstash, upon restarting my whole VM locked up and I had to restart the entire thing! Logstash didn't write to any of the logs (it's set to debug mode) and I had to just remove the grok pattern.
Hi there @magnusbaeck I think I found out why the VM crashed. Logsash log level was set to DEBUG, once I got back into the VM (as Logstash doesn't automatically start when the VM does) I found there to be around 15GB of log files created by Logstash. I will set the log level to normal and retry the grok.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.