I'm new to logstash and of course one of the first log sources I try to bring in is a weird one. The server is a VMWare Horizon ID server and it's sending some very weird timestamps.
So far I know that the format is year.month.dayoftheyear(today is day 129) and then HH:MM but have no clue on the 360. Does anyone know of a way to grok and change this time stamp into normal parameters for ingestion?
Ok so I've made it further. I'm trying now to get the field dayofyear converted to the day of the month. Seems I need Ruby for this, but I haven't been able to cobble together working code. Ideas?
day of year is represented with D as per the date filter plugin docs. i suppose the other three digits represents fractions of seconds? if so, you can update your grok capture the whole timestamp with a single grok expression , then parse it with date filter using yyyy-MM-D HH:mm:SSS
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.