I have dates extracted from the log lines using the
date filter. I want to drop any log line which is older than 5 days and not put it into Elasticsearch at all.
Is there a standard filter which does this or at least identifies older log lines already or do I need to use a
ruby filter? Due to complications with corporate process (please don't ask) it would be hard for me to install a community plugin which isn't included with the normal Logstash installation.
This issue has come up as sometimes we start Logstash on a VM which hasn't been run in a while and ancient log files get picked up which we don't want.