elasticsearch,logstash,Datetime,elasticsearch,Logstash" /> elasticsearch,logstash,Datetime,elasticsearch,Logstash" />

Datetime 弹性搜索日期解析错误

Datetime 弹性搜索日期解析错误,datetime,elasticsearch,logstash,Datetime,elasticsearch,Logstash,我对配置elastic非常陌生,在尝试解析日志日期时遇到了问题——这似乎应该是一件小事 对新手有什么见解吗 "error": { "root_cause": [ { "type": "mapper_parsing_exception", "reason": "failed to parse [Message.LogTime]" } ], "type": "mapper_par

我对配置elastic非常陌生,在尝试解析日志日期时遇到了问题——这似乎应该是一件小事

对新手有什么见解吗

 "error": {
      "root_cause": [
         {
            "type": "mapper_parsing_exception",
            "reason": "failed to parse [Message.LogTime]"
         }
      ],
      "type": "mapper_parsing_exception",
      "reason": "failed to parse [Message.LogTime]",
      "caused_by": {
         "type": "illegal_argument_exception",
         "reason": "Invalid format: \"2015-11-12 01:37:35.490\" is malformed at \" 01:37:35.490\""
      }
   }
我的JSON负载

  {
    "LoggerType": "ErrorAndInfo",
    "Message": {
      "LogId": 0,
      "LogStatus": 0,
      "LogTime": "2015-11-12 01:37:35.490",
      "VersionInfo": "",
      "AdditionalInformation": null
    }
  }
弹性搜索模板映射

"mappings": {
    "log_message" : {
      "_all" : { "enabled": false },
      "properties": {
        "LoggerType" : { "type" : "string" },
        "Message" : {
          "properties": { 
            "LogId": { "type" : "integer" },         
            "LogStatus": { "type" : "integer" },
            "LogTime": { 
              "type" : "date",
              "format" : "yyyy-MM-dd HH:mm:ss.SSS"
            },
            "VersionInfo": { 
              "type" : "string",
              "index" : "not_analyzed"
            },
          }
        }
      }
    }
  }

我想出来了。您必须为要应用的更改重新创建索引

我在创建索引和索引示例文档方面没有遇到任何问题。能否显示正在运行的命令1)创建索引+映射,2)为文档编制索引?