Hello.
First of all, I'm using Fluentd with creating statistics, log search by ES, etc.
Thanks for all your great works!
I have a question.
My favorite plugin 'fluent-plugin-elasticsearch' has an action related to @timestamp key.
But I'm having a hard time to define key to @timestamp.
1. record_reformer
Below is failed from latest release of Fluentd.
<record>
@timestamp ${time_year}-${time_month}-${time_day}T${time_hour}:${time_minute}:${time_second}.${time_millisecond}+09:00
</record>
Fluentd v10 Config Parser doesn't allow @ from line start. So it says "parse error".
2. parser
format /^(?<@timestamp>[0-9]{4}-[0-9]{2}[0-9]{2} [0-9]{2}:[0-9]{2}:[0-9]{2}\.[0-9]{3})\s+~blabla~/
It fails with complaining @ is not acceptable for group name.
How can I use @timestamp key? Is there another plugin that renames key with @timestamp with respecting Fluentd v10 Config Parser?
Thanks in advance.
Regards.
Jungtaek Lim (HeartSaVioR)