Aruba syslog timestamp pattern
Posted: Tue Aug 22, 2023 3:14 pm
Hi,
I am seeking help to get timestamp pattern properly matched. Here is the error in the logstash log:
{:timestamp=>"2023-08-22T11:33:40.818000-0700", :message=>"Failed parsing date from field", :field=>"log_date", :value=>"Aug 22 11:33:40.107 PDT", :exception=>"Invalid format: \"Aug 22 11:33:40.107 PDT\"", :config_parsers=>"MMM dd HH:mm:ss.SSS ZZZ,MMM dd HH:mm:ss ZZZ,MMM dd HH:mm:ss.SSS,YYYY MMM dd HH:mm:ss.SSS ZZZ,YYYY MMM dd HH:mm:ss ZZZ,YYYY MMM dd HH:mm:ss.SSS,ISO8601", :config_locale=>"default=en_US", :level=>:warn}
Here is what I have in the filter date session:
date {
match => [ "syslog_timestamp", "ISO8601", "MMM d HH:mm:ss", "MMM dd HH:mm:ss", "MMM dd HH:mm:ss.SSS" ]
timezone => "-0800"
remove_field => "syslog_timestamp"
}
I am seeking help to get timestamp pattern properly matched. Here is the error in the logstash log:
{:timestamp=>"2023-08-22T11:33:40.818000-0700", :message=>"Failed parsing date from field", :field=>"log_date", :value=>"Aug 22 11:33:40.107 PDT", :exception=>"Invalid format: \"Aug 22 11:33:40.107 PDT\"", :config_parsers=>"MMM dd HH:mm:ss.SSS ZZZ,MMM dd HH:mm:ss ZZZ,MMM dd HH:mm:ss.SSS,YYYY MMM dd HH:mm:ss.SSS ZZZ,YYYY MMM dd HH:mm:ss ZZZ,YYYY MMM dd HH:mm:ss.SSS,ISO8601", :config_locale=>"default=en_US", :level=>:warn}
Here is what I have in the filter date session:
date {
match => [ "syslog_timestamp", "ISO8601", "MMM d HH:mm:ss", "MMM dd HH:mm:ss", "MMM dd HH:mm:ss.SSS" ]
timezone => "-0800"
remove_field => "syslog_timestamp"
}