if "one-sync" in [tags] and "heart-sync" in [tags] and "edemand" in [tags] and "events" in [tags] {
date {
match => ["timestamp", "yyyy-MM-dd'T'HH:mm:ss'.'SSS'Z'"]
timezone => "GMT"
target => "@timestamp"}
log looks like this:
{"level":"debug","message":"Received resonse 4611 ","timestamp":"2022-05-26T12:06:11.079Z"}
If there is no _dateparsefailure tag then either the source field does not exist or the conditional is preventing the date filter from processing the event.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.