Remove message and replace timestamp fields

You can remove a field using mutate

mutate { remove_field => [ "message" ] }

Use a date filter to parse app_timestamp and overwrite @timestamp.

1 Like