I think you could just do something like:
ruby {
init => "require 'time'"
code => "event['time_difference'] = event['received_at'] - event['@timestamp'];"
}
I think you could just do something like:
ruby {
init => "require 'time'"
code => "event['time_difference'] = event['received_at'] - event['@timestamp'];"
}
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.