In my oracle DB, I have with timestamp like this: "createdDate" => 2022-04-02T17:00:44.339Z
But in my elasticsearch index, having createdDate as "createdDate": "2022-04-02T17:00:44Z"
How can we change the format in Logstash configuration?

I tried using grok filter below. Not resolved. Could you please suggest?

match => {
"created_date" => "%{GREEDYDATA:createdDate}.%{GREEDYDATA:time1}"


Hello @suresh_u

You can try this below which would work

mutate {
gsub => ["createdDate", ".\d{3}", ""]

thank you so much for your quick solution. @sudhagar_ramesh

