I fall asleep my magazines in Elasticsearch. Therefore, to create an index by the date of registration in it timestamp, I use the date filter as follows:
date { "locale" => "en" match => ["timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss", "ISO8601"] target => "@timestamp" }
I use logs from syslog and the timestamp syslog doest format has no year:
So, after using the date filter, the created index looks like logstash-2015.12.26 if I read the journal on December 26th, 2014. Since the timestamp is not available in the log, it selects the current year by default.
Any idea how to make the correct index?
source share