1.i have log_time field and want to load it @timestamp with date filter. but there is time difference after i load it to @timestamp example: log_time is 09:34, but @timestamp is 05:34. i know @timestamp work on utc timezone, now how can solve this problem and load correct time to @timestamp
2.I have very big indicies nearly 3000, and it is working very slow how can i customize it.
As you pointed out, the @timestamp field has to be in UTC timezone, so I am not sure what you mean by correcting it. Which timezone is the log_time field in? What would you expect @timestamp to be?
Having very large number of indices and/or shards can be very inefficient and cause performance problems. Please read this blog post for some practical guidelines.
and it is filter which i use
filter {
if [type] == "prod_user_login" {
csv {
separator => ","
columns => ["UserID","User Type","Role Name","Login Date"]
add_tag => [ "PROD_USER_LOGIN" ]
remove_field => ["message"]
}
date {
match => ["Login Date", "dd/MM/yyyy HH:mm"]
}
}
}
That looks like the correct UTC timestamp corresponding to the Sydney timezone timestamp. As timestamps in Elasticsearch has to be in UTC, I do not see what the problem is.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.