i am not really sure what the last part is (the ":100:")
The beginning would be: yyyy-MM-ddTHH:mm:ss.SSS
All after the millisecond is non standard and i think it will have to be transformed with a ruby filter. (The only way i can think of)
Input:
req_dtm - 2019-07-26T00:00:16.266+02:00
Date Filter to change format
date {
match => [ "req_dtm", "yyyy-MM-dd'T'HH:mm:ss.SSS" ]
target => "request_dtm"
}
Output: _dateparsefailure
Input:
trans_dtm - 2019-07-26 00:00:16,562
Date Filter to change format
date {
match => [ "trans_dtm", "yyyy-MM-dd HH:mm:ss,SSS" ]
target => "response_dtm"
}
Output: 2019-07-26T00:00:16.562Z -- Looks OK.
Kindly suggest how to handle the first one which is resulting in parsing failure.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.