Formatting a log today, the date is not easy to get, it is divided into two fields.
Later date supports another field
date {
match => ["time", "yyyy-MM-dd HH:mm:ss.SSS" ]
}
The merge of mutate is useless, and the two fields are combined into an array.
Finally found a solution, use alter
alter{
add_field => { "fullTime" => "%{day} %{time}" }
}
Then the date converts perfectly
date {
match => ["fullTime", "yyyy-MM-dd HH:mm:ss.SSS" ]
}