gpt4 book ai didi

elasticsearch - 将消息中的日期替换为Logstash中的@timestamp

转载 作者:行者123 更新时间:2023-12-03 01:53:04 27 4
gpt4 key购买 nike

我有此日志http://wklej.org/id/2777228/,我希望此日志中的日期成为时间戳。我的配置文件:

http://wklej.org/id/2777231/

但是这还行。 http://wklej.org/id/2777230/

最佳答案

这是我尝试过的,对我有用:

filter {
grok{
match => {"message" => "%{TIMESTAMP_ISO8601:myTimestamp}"}
}
date {
locale => "en"
match => ["myTimestamp", "YYYY-MM-dd HH:mm:ss,SSS", "ISO8601"]
timezone => "Europe/Warsaw"
add_field => { "debug" => "timestampMatched"}
}
}

输出:
  "_source": {
"message": "2016-08-03 10:19:44,503 [DEBUG] NHibernate.SQL: SELECT this_.ID as ID6_0_, this_.Valor as Valor6_0_, this_.ANALYTIC_DATA_ID as ANALYTIC3",
"@version": "1",
"@timestamp": "2016-08-03T08:19:44.503Z",
"host": "RST-Mrunal",
"myTimestamp": "2016-08-03 10:19:44,503",
"debug": "timestampMatched"
}

希望能帮助到你!

关于elasticsearch - 将消息中的日期替换为Logstash中的@timestamp,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/38740687/

27 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com