With the date fields below commented out, I get events logged, but with the wrong timestamp. Removing the comment I get nothing logged and no error messages, at least that I can find. The timezone line doesn't matter either.
More research, no solution. With this code in the date block above
date {
match => [ "log_timestamp", "YYYY-MM-dd HH:mm:ss" ]
remove_field => [ "log_timestamp" ]
target => "log_timestamp_test"
}
log_timestamp_test has the tiny clock icon and a sample displays as December 21st 2016, 03:11:42.000 and the log_timestamp field is dropped, so I know it's going thru the code
If I make the target => "@timestamp", I still don't get anything sent to elasticsearch.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.