filter {
grok{
match => [
"message","\[%{TIMESTAMP_ISO8601:TimeStamp}\]"
]
}
date {
match => [ "TimeStamp", "ISO8601" ]
target => "timestamp"
timezone => "Asia/Shanghai"
}
}
i input [2018-04-13 15:00:00.000]
[2018-04-13T15:36:14,470][WARN ][logstash.outputs.elasticsearch] Could not index
event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>
"logstash(2018.04.13)", :_type=>"logstash", :_routing=>nil}, #<LogStash::Event:0
x10ad1942>], :response=>{"index"=>{"_index"=>"logstash(2018.04.13)", "_type"=>"l
ogstash", "_id"=>"g0vuvWIBoK0nbYCH664-", "status"=>400, "error"=>{"type"=>"mappe
r_parsing_exception", "reason"=>"failed to parse [TimeStamp]", "caused_by"=>{"ty
pe"=>"illegal_argument_exception", "reason"=>"Invalid format: "2018-04-13 15:00
:00.000" is malformed at " 15:00:00.000""}}}}}
{
"@timestamp" => 2018-04-13T07:36:14.303Z,
"host" => "BIH-D-6331",
"@version" => "1",
"TimeStamp" => "2018-04-13 15:00:00.000",
"message" => "[2018-04-13 15:00:00.000]\r",
"timestamp" => 2018-04-13T07:00:00.000Z
}