Optimize Transport App to Logstash Forwarder to LogStash Indexer to Elasticsearch

My app generates JSON the following in log files:


The idea is logstash Indexer will not have to create @timestamp. Logstash Forwarder adds a field type and set it to "myapp".

filter {
if [type] == "myapp" {
json {
source => "message"

All seems to work fine, but I'm not sure that adding @timestamp in my log message would help reducing the workload logstash indexer has to do. Is my @timestamp in the correct format or does Logstash Forwarder still have to convert it to a timemillis format?


Your @timestamp field looks exactly like something Logstash's date filter would produce.