Supported Log Event Timestamp Formats
One of the key things when working with time based data is the timestamp that represents the moment when the event was generated. Sematext Logs Management expects the time of the event to be provided in the
@timestamp field. The following
@timestamp value formats are currently supported by our logging management solution:
ISO date with timezone information, for example:
2016-06-22T10:00:00Z 2016-01-04T15:30:10.474+00:00 2016-01-04T15:30:10,474+00:00 2016-06-22T10:00:00.000Z 2016-06-22T10:00:00,000Z 2016-06-22T10:00:00Z 2016-06-22T10:00:00.298Z 2016-06-22T10:00:00.298
Timezone specified by using +/- notation, for example:
Default Log4j date and time format, for example:
2016-06-24 10:38:09,758 2016-06-24 10:38:09
Time since epoch, for example:
Graylog date format, for example:
1385053862.3072 1444128321.426 2015-11-13T09:21:45.298
NGINX non-ISO date format, for example:
@timestampfield is not provided Sematext will set
@timestampto the time when the event is received by Sematext.
- if the
@timestampfield is not parsable by Sematext, the
@timestampfield will be set to the time when the event is received by Sematext.
- if time specified in
@timestampdoes not include timezone information, the Logs App will assume UTC.