I've got a box running Kibana and Elasticsearch, with the information being handed across by fluentd rather than logstash. In hindsight I'd have picked Logstash, but the guide at the time covered fluentd. It's all working pretty well, and I've moved on to pushing Windows events through - which is where I'm struggling.
I'm using nxlog on the windows machines, and it's pushing the data directly to elasticsearch - unfortunately I cannot for love nor money get the date to be handled as a date, rather than a string. While beyond the scope of this forum (I assume), then nxlog output is:
I create a new index with a pattern of windowsevents*, but the EventTime field is stated as a string, not a date - so I can't sort data by age. @timestamp clearly isn't getting populated, as the timestamp field isn#t being used. Has anyone used a similar setup? Is there a way to ask Elastic to treat a field as a date?
Apologies if I've missed out pertinent information - it's all a bit new to me.
Thank you; I suspected that might be the case, but I wasn't sure if there was a means of specifying the data type within elastic/kibana. I wasn't having much luck on the nxlog side. Cheers!
I am not familiar with fluentd, so do not know if it provides some type of default mapping like Logstash does or not. Check if you have any index templates defined that would apply to the index these logs go into. If this is the case you should be able to modify the mapping for the timestamp field so that Elasticsearch maps it as a date.
You're a hero, thank you. Using the information you referenced, I displayed the templates in use by elasticsearch, and checked the JSON information in Kibana.
I was pushing the information in as "windowsevents", and using "windowsevents*" as an index template. Obviously I got a bit confused when I was following some other information, and went rogue with the names. I changed the output to read "nxlog*", and bingo! I get presented with "EventTime" as a Time-Field option.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.