应用场景:logstash推上了时间戳类型,es无法直接识别
解决方法:
在模板上配置properties的时候指定字段的类型和格式
"time": {
"format": "epoch_second",
"type": "date"
}
"@timestamp": {
"format": "strict_date_optional_time||epoch_millis",
"type": "date"
}
"time_local": {
"format": "dd/MMM/yyyy:HH:mm:ss Z",
"type": "date"
}
参考文档:https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-date-format.html