I have date value like 15 May 2017 11:52:59 IST
Here I am not sure how to handle IST
Please suggest in Logstash what date format I can apply on this value .
I used
date {match => ["endTime","dd MMM YYYY HH:mm:ss","ISO8601"] target => "endTime"} OR
date {match => ["endTime","dd MMM YYYY HH:mm:ss Z"] target => "endTime"}
The date filter can't parse timezone names. Two options:
If the timestamp is always IST, hardcode a suitable timezone in the date filter's timezone option and use dd MMM yyyy HH:mm:ss 'IST' is your date filter pattern.
If the timezone can vary, extract it into a field and feed it through a translate filter to transform it into a UTC offset that the date filter can parse.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.