Initial setup instructions: how to take the timestamp from the log?

First time trying this out, and I have successfully got through the excellent Getting Started instructions. It is working.

Some feedback and a question:

It did seem a bit odd that all the datapoints had the same timestamp. This is seen in the Kibana screenshot too.

https://www.elastic.co/guide/en/logstash/6.7/advanced-pipeline.html

As far as I can see, by default the timestamp for each event is the time it was received by logstash, and not the actual timestamp in the logfile.

Is there an example of a logstash configuration file showing how to get the events to use the timestamp from a standard logfile such as Apache?

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.