# Cannot get original timestamp from WSo2 logs coming from Source -\> filebeat -\> logstash -\> Elasticsearch

**URL:** <https://discuss.elastic.co/t/cannot-get-original-timestamp-from-wso2-logs-coming-from-source-filebeat-logstash-elasticsearch/275148>\
**Category:** Logstash\
**Created:** [June 7, 2021, 12:16pm UTC](https://discuss.elastic.co/t/cannot-get-original-timestamp-from-wso2-logs-coming-from-source-filebeat-logstash-elasticsearch/275148 "2021-06-07T12:16:31Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jefledge](https://avatars.discourse-cdn.com/v4/letter/j/48db29/32.png) [@Jefledge](https://discuss.elastic.co/u/Jefledge)\
**Post date:** [June 7, 2021, 12:16pm UTC](https://discuss.elastic.co/t/cannot-get-original-timestamp-from-wso2-logs-coming-from-source-filebeat-logstash-elasticsearch/275148/1 "2021-06-07T12:16:31Z")

</div>

I currently have logstash and filebeat running on the same AWS EC2 as a proof of concept to get logs from efs and push to Elastic for us to view on Kibana. It is all set up and working nicely, there is just one issue I cant seem to figure out and thats getting the original WSo2 Log timestamp to come through all the way to Kibana and use that as the @timestamp field. I assume its something I am doing wrong on logstash config from what I have read, that is where I should be setting it.

Config is as follows:

```auto
input {
    beats {
         type => "beats"
         host => "127.0.0.1"
         port => 5044
    }
}
filter {
  if [type] == "beats" {
    grok {
      match => { "message" => "\[%{TIMESTAMP_ISO8601:timestamp}\] %{SPACE}%{SPACE}%{LOGLEVEL:level}%{SPACE}%{NOTSPACE:class}%{SPACE}-%{SPACE}%{SPACE}%{JAVALOGMESSAGE:log_message}" }
      tag_on_failure => ["failed-to-parse"]
      remove_field => ["message"]
    }
    date {
      match => ["timestamp", "yyyy-MM-dd HH:mm:ss,SSS"]
      target => "@timestamp"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 7, 2021, 4:59pm UTC](https://discuss.elastic.co/t/cannot-get-original-timestamp-from-wso2-logs-coming-from-source-filebeat-logstash-elasticsearch/275148/2 "2021-06-07T16:59:19Z")

</div>

What does a message look like?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2021, 4:59pm UTC](https://discuss.elastic.co/t/cannot-get-original-timestamp-from-wso2-logs-coming-from-source-filebeat-logstash-elasticsearch/275148/3 "2021-07-05T16:59:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
