Help us understand the problem. What is going on with this article?

super_mediatorを改造せずにlogstashのフィルタで@timestampの値をflows.flowStartMillisecondsにする

More than 1 year has passed since last update.

pcapファイルをIPfixに変換、ELKで可視化
https://qiita.com/t_umeno/items/999a9f1e76b9cffa1053
の補足です。
上記URLではsuper_mediatorを改造しましたが、
super_mediatorを改造せずに
logstashのフィルタで@timestampの値をflows.flowStartMillisecondsにする事ができます。

matchのフォーマットの部分に

"yyyy-MM-dd HH:mm:ss.SSS"

と書けば変換できます。
下記の例ではsuper_mediator改造して、ISO8601形式に変更した場合も考慮しています。
2018/02/25 追記
timezone としてUTCを指定する様にしました。timezoneを指定しないとOS
で指定したtimezoneで時刻が取り扱われてしまいます。
例:

filter {
    if ([type] == "ipfix") {
        grok {
            match => ["path", "(?<index>yaf.\d{8,14})\.json$" ]
        }
        date {
            locale => "en"
            match => ["[flows][flowStartMilliseconds]", "yyyy-MM-dd HH:mm:ss.SSS", "ISO8601"]
            target => "@timestamp"
            timezone => "UTC"
        }
        date {
            locale => "en"
            match => ["[flows][flowStartMilliseconds]", "yyyy-MM-dd HH:mm:ss.SSS", "ISO8601"]
            target => "[flows][flowStartMilliseconds]"
            timezone => "UTC"
        }
        date {
            locale => "en"
            match => ["[flows][flowEndMilliseconds]", "yyyy-MM-dd HH:mm:ss.SSS", "ISO8601"]
            target => "[flows][flowEndMilliseconds]"
            timezone => "UTC"
        }
    }
}
Why not register and get more from Qiita?
  1. We will deliver articles that match you
    By following users and tags, you can catch up information on technical fields that you are interested in as a whole
  2. you can read useful information later efficiently
    By "stocking" the articles you like, you can search right away
Comments
No comments
Sign up for free and join this conversation.
If you already have a Qiita account
Why do not you register as a user and use Qiita more conveniently?
You need to log in to use this function. Qiita can be used more conveniently after logging in.
You seem to be reading articles frequently this month. Qiita can be used more conveniently after logging in.
  1. We will deliver articles that match you
    By following users and tags, you can catch up information on technical fields that you are interested in as a whole
  2. you can read useful information later efficiently
    By "stocking" the articles you like, you can search right away
ユーザーは見つかりませんでした