@badger Now, the date is not even getting calculated correctly. I'll add another question with json for this issue and then we can look for the date field type conversion. But, just for the reference I'll paste the json here:
{
"_index": "filebeat-6.2.4-2018.06.22-index",
"_type": "doc",
"_id": "AxpzJ2QB3tEACYuyWrVz",
"_version": 2,
"_score": null,
"_source": {
"zimbra_proc_end_time": "2018-01-01T09:32:46.000Z",
"tags": [
"umm-logs-zimbra-proc-failure",
"beats_input_codec_plain_applied"
],
"source": "/opt/openvault/umm/logs/ummProcess.log",
"host": "ip-192-168-0-139",
"offset": 308705,
"log_level": "INFO",
"start_date": "17 Apr 2018",
"prospector": {
"type": "log"
},
"day": "Tue",
"end_date": "17 Apr 2018",
"@timestamp": "2018-06-22T12:23:44.474Z",
"zimbra_proc_start_time": "2018-01-01T09:32:45.000Z",
"beat": {
"name": "ip-192-168-0-139",
"hostname": "ip-192-168-0-139",
"version": "6.2.4"
},
"@version": "1",
"message": "17 Apr 2018 09:32:45\tINFO\tZimbra notification file generation started at: Tue Apr 17 09:32:45 CDT 2018\n17 Apr 2018 09:32:45\tINFO\t Executing Zimbra file generation process\nWarning: Using a password on the command line interface can be insecure.\n17 Apr 2018 09:32:46\tINFO\tFinished at: Tue Apr 17 09:32:46 CDT 2018"
},
"fields": {
"@timestamp": [
"2018-06-22T12:23:44.474Z"
],
"zimbra_proc_time": [
1
],
"zimbra_proc_end_time": [
"2018-01-01T09:32:46.000Z"
],
"csg_proc_time": [
""
],
"perftech_proc_time": [
""
],
"zimbra_proc_start_time": [
"2018-01-01T09:32:45.000Z"
]
},
"sort": [
1514799165000
]
}
As you could see, the date calculation absolutely doesn't make any sense at all here which is strange.
The only change I did was to add 'T'
:
date {
match => [ "start_date_parse", "yyyy-MM-dd'T'HH:mm:ss.SSSZ", "HH:mm:ss", "dd MMM yyyy HH:mm:ss.SSSZ", "d MMM yyyy HH:mm:ss.SSSZ" ]
target => "zimbra_proc_start_time"
}
date {
match => [ "end_date_parse", "yyyy-MM-dd'T'HH:mm:ss.SSSZ", "HH:mm:ss", "dd MMM yyyy HH:mm:ss.SSSZ", "d MMM yyyy HH:mm:ss.SSSZ" ]
target => "zimbra_proc_end_time"
}
And time format is: HH:mm:ss
zimbra_proc_start_time: 09:40:41