I am trying to replace @timestamp with syslog_timestamp using date filter, But it's not working. My log format is:
Jan 20 16:18:41 staging1 frontend [22.214.171.124] << "POST /oauth/authenticate"
My logstash.conf is:
I am trying to make it work from last 2 days, Finally I thought of asking you guys, Kindly help please.
Are you sure your grok filter is applied correctly. No "_grokparsefailure" ?
Can you please post a sample event and the output of stdout
No reply from user, feel free to re-open if it is still an issue