我的csv: 122373396 | 1 | 3 | 3 | 1595829648 | 899 | 4 | 0525179 ** 2 | 425030006017669 |||| 16 | 3573771081579101 || 6435 | 6654 | 0 | 6654 | 5577 | 4 | 6435 | 0 | 0 | 2 | 2
时间是1595829648
input{
file{
path => "D:/elk/modulo.txt"
start_position => "beginning"
sincedb_path => "null"
}
}
filter{
csv{
separator => "|"
columns => ["Event_ID","Event_Type","Event_Code","Call_Type","Event_Time","Event_Time_MS","Duration","Calling_Party","Calling_IMSI","Called_Party","Called_IMSI","Redirecting_Party","Release_Cause","Calling_IMEI","Called_IMEI","OPC","SPC","CIC","Calling_Switch","Calling_Cell","Calling_Sector","Called_Switch","Called_Cell","Called_Sector","Calling_Network_Type","Called_Network_Type"]
}
date {
match => [ "Event_Time" , "dd/MMM/yyyy:HH:mm:ss" ]
target => "Event_Time"
}
}
output{
csv{
path => "D:/elk/log/mlog.txt"
fields => ["Event_ID","Event_Type","Event_Code","Call_Type","Event_Time","Event_Time_MS","Duration","Calling_Party","Calling_IMSI","Called_Party","Called_IMSI","Redirecting_Party","Release_Cause","Calling_IMEI","Called_IMEI","OPC","SPC","CIC","Calling_Switch","Calling_Cell","Calling_Sector","Called_Switch","Called_Cell","Called_Sector","Calling_Network_Type","Called_Network_Type"]
}
}
输出文件中的日期保持不变