Can you add stdout { codec => rubydebug } to the output part and show us the result when you have a no_date_found please.
Because currently the grok pattern work.
grok does not need to consume the entire field it is matching against. The grok pattern that Miguel gave matches "09/10/2021, 8:30:00", and when tested in logstash it matches.
Consuming the AM affects the value of the timestamp (at least when it is PM) but does not prevent the grok pattern matching.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.