Thanks for your help in this question. I would like to change the Timestamp in Graylog to provide the Timestamp coming from the logs collected by filebeat. In order to achieve this, I have created an extractor using regular expression and saved it as a field “Timestamp” as follows:
The problem is that in Graylog search I have an inconsistency of Timestamp and timestamp fields. The current timestamp which corresponds to the time the log was processed is in Timestamp and timestamp field and I have another Timestamp field which has the time related to the log. To clarify the scenario I provide an screenshot of the mentioned behaviour:
Can you please help to clarify this behaviour? and indicate how to fix this?
Thanks a lot, I appreciate your help.