I am curently parsing azure messages. Sadly azure sends some dates in the following format:
2018-06-03 01:00:12Z
at first I thought this would be a normal ISO8601 but this did not match. I tried a Formats like yyyy-MM-dd HH:mm:ssZ and yyyy-MM-dd HH:mm:ss but this did not work also. Do I have to remove the Z at the end of the Azure timestamp?
Yes this was an error by elasticsearch. I dont know why, but i tested the config and viewed the output via output on stdout and everything seemed fine with the 'Z'. For now this error hasent apeared since. I will report back to you guys if it happens again.
If you index a field that contains "2018-06-03" then elasticsearch expects that field to contain a date. "2018-06-03 01:00:12Z" is not a date, it is a timestamp. So it will complain about the field format all day, until it rolls to a new index, at which point it starts expecting the field to contain a timestamp. (Assuming you do not have a template forcing the field format.)
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.