I think it's always nice to ask an actual question in a post. Anyway, you can do that easily with a Ruby filter:
ruby {
code => 'event.set("lag", event.get("@timestamp")-event.get("event_timestamp"))'
}
I think it's always nice to ask an actual question in a post. Anyway, you can do that easily with a Ruby filter:
ruby {
code => 'event.set("lag", event.get("@timestamp")-event.get("event_timestamp"))'
}
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.