i am quite new to this and would need some help understanding the Grok Patterns. I have tho following:
date=2020-06-30 time=09:21:14 devname="600E" devid="FG6H0E5819904479" logid="0000000013" type="traffic" subtype="forward" level="notice" vd="root" eventtime=1593501674337461223 tz="+0200"
i want to create an Extractor using Grok Pattern.
I started like this (I want year,month,day in separated fields):
which worked fine. How do I proceed from there i tried many of the time patten but none seem to work, or I (most likely use them wrong).
Maybe a kind soul can give me a push by highlighting how i can format the first 3-4 fields, I would highly appreciate it .