filter {
mutate{
gsub => [ "RecordTime", "T", " " ]
gsub => [ "CreateTimeString", "<br/> ", " " ]
add_field => {
"Myyyy"=>"%{RecordTime}"
"MMM"=>"%{RecordTime}"
"Mdd"=>"%{RecordTime}"
}
}
date{
match => [ "RecordTime", "yyyy-MM-dd HH:mm:ss"]
target => "@timestamp"
timezone => "+00:00"
match => [ "Myyyy", "yyyy"]
match => [ "MMM", "MM"]
match => [ "Mdd", "dd"]
}
mutate{
remove_field => ["tags","@version"]
}
}
想获取时间的年、月、日 有啥其他办法吗。 这种不行
mutate{
gsub => [ "RecordTime", "T", " " ]
gsub => [ "CreateTimeString", "<br/> ", " " ]
add_field => {
"Myyyy"=>"%{RecordTime}"
"MMM"=>"%{RecordTime}"
"Mdd"=>"%{RecordTime}"
}
}
date{
match => [ "RecordTime", "yyyy-MM-dd HH:mm:ss"]
target => "@timestamp"
timezone => "+00:00"
match => [ "Myyyy", "yyyy"]
match => [ "MMM", "MM"]
match => [ "Mdd", "dd"]
}
mutate{
remove_field => ["tags","@version"]
}
}
想获取时间的年、月、日 有啥其他办法吗。 这种不行
7 个回复
GLC
赞同来自:
Myyyy
MMM
Mdd
最后还是时间格式 ,并非想要的年、月、日
zqc0512 - andy zhou
赞同来自:
GLC
赞同来自:
GLC
赞同来自:
zqc0512 - andy zhou
赞同来自:
GLC
赞同来自:
match => [ "MMM", "MM"]
match => [ "Mdd", "dd"]
这些 就是做处理的。@zqc0512
zqc0512 - andy zhou
赞同来自: