below info is my logstash conf
can i define index name timezone ??
filter {
grok {
match => { "message" => "%{TIMESTAMP_ISO8601:datatime} %{LOGLEVEL:loglevel} - %{IP:client} %{NUMBER:duration} %{WORD:qtype} %{DATA:domain} %{NUMBER:nb1} %{NUMBER:nb2} " }
}
date {
locale => "en"
match => ["datatime","YYYY-MM-dd HH:mm:ss"]
timezone => "Asia/Shanghai"
}
}
output {
elasticsearch {
hosts => ["18.41.15.14:9200","18.41.15.15:9200"]
index => "logstash-%{[fields][logtype]}-%{+YYYY.MM.dd}"