Recently, we upgraded our production machine which meant I would have to re-deploy Filebeat on this new server. All the log paths and log formats are the same, however, for whatever reason, it is having an issue with logdate.
This was not an issue with the old production server so I am a little confused why it is an issue with the new server with the same log data.
date {
match => ["logdate", "yyyy-MM-dd HH:mm:ss,SSS"]
target => "logdate"
timezone => "US/Pacific"
}
Nothing in my configuration has changed. This is what I see when I use the timestamp date histogram.