title: 解决es存储时差8小时问题 #标题tags: es #标签
date: 2020-11-22
categories: elastic stack # 分类

记录es存储数据时差8小时问题。

  1. # ruby 主要是将 req_time + 8小时后赋值给timestamp
  2. ruby {
  3. code => "event.set('timestamp', event.get('req_time') + 8*60*60*1000)"
  4. }
  5. date {
  6. match => ["timestamp", "UNIX_MS"]
  7. target => "@timestamp"
  8. }
  9. mutate {
  10. remove_field => ["timestamp"]
  11. }