# Changing time zone format

**URL:** <https://discuss.elastic.co/t/changing-time-zone-format/71775>\
**Category:** Logstash\
**Created:** [January 16, 2017, 6:47pm UTC](https://discuss.elastic.co/t/changing-time-zone-format/71775 "2017-01-16T18:47:38Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dan](https://avatars.discourse-cdn.com/v4/letter/d/eada6e/32.png) [@Dan](https://discuss.elastic.co/u/Dan)\
**Post date:** [January 16, 2017, 6:47pm UTC](https://discuss.elastic.co/t/changing-time-zone-format/71775/1 "2017-01-16T18:47:39Z")

</div>

i am using jdbc as input and http as output.

from jdbc i am getting date as **"2017-01-02T12:35:44.000Z"**  
but in my http output date will be accept as **"2017-01-02T12:35:44.000+07:00"**

when i am checking inn database there not mentioned any timezone.But in output i am getting **z**

Ho w can i convert from **"2017-01-02T12:35:44.000Z"** to **"2017-01-02T12:35:44.000+07:00"** format.

Thanks in Advance......

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 16, 2017, 11:21pm UTC](https://discuss.elastic.co/t/changing-time-zone-format/71775/2 "2017-01-16T23:21:19Z")

</div>

Logstash uses the system timezone, so what is that set to on the host LS runs on?

---

<div class="post-metadata">

**Author:** ![Dan](https://avatars.discourse-cdn.com/v4/letter/d/eada6e/32.png) [@Dan](https://discuss.elastic.co/u/Dan)\
**Post date:** [January 17, 2017, 4:19am UTC](https://discuss.elastic.co/t/changing-time-zone-format/71775/3 "2017-01-17T04:19:05Z")

</div>

Thanks Mark for your quick reply...

but in my http output accept only **"2017-01-02T12:35:44.000+07:00"** this format.

To remove **z** in my time format i am using below filter.

mutate {  
gsub =\> [  
"%{cycle\_time}", "z", ""  
]  
}

But it's not working for [me.My](http://me.My) goal is to remove **z**.  
you have working example of gsub or grok or with any other filter.

Please help me how can avoid z in my Time.

Thanks in Advance.....

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 17, 2017, 6:31am UTC](https://discuss.elastic.co/t/changing-time-zone-format/71775/4 "2017-01-17T06:31:56Z")

</div>

The first element of the array you feed to gsub should contain the _name_ of the field, not its contents (i.e. use `cycle_time` not `%{cycle_time}`). Also, keep in mind that regexp matching is case-sensitive by default.

---

<div class="post-metadata">

**Author:** ![Dan](https://avatars.discourse-cdn.com/v4/letter/d/eada6e/32.png) [@Dan](https://discuss.elastic.co/u/Dan)\
**Post date:** [January 18, 2017, 3:58am UTC](https://discuss.elastic.co/t/changing-time-zone-format/71775/5 "2017-01-18T03:58:47Z")

</div>

I tried (use cycle\_time not %{cycle\_time})) this.

This is not working.

> [@Dan](#):
>
> mutate { gsub =\> ["cycle\_time", "z", ""]}

Please suggest me is there any other solution.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 18, 2017, 6:29am UTC](https://discuss.elastic.co/t/changing-time-zone-format/71775/6 "2017-01-18T06:29:47Z")

</div>

Did you try with a capital "Z" instead of "z"?

---

<div class="post-metadata">

**Author:** ![Dan](https://avatars.discourse-cdn.com/v4/letter/d/eada6e/32.png) [@Dan](https://discuss.elastic.co/u/Dan)\
**Post date:** [January 18, 2017, 7:18am UTC](https://discuss.elastic.co/t/changing-time-zone-format/71775/7 "2017-01-18T07:18:02Z")

</div>

Yes,I tried with capital Z.  
getting **gsub mutation is only applicable for Strings**.

for the above error i tried

mutate {  
add\_field =\> {"testcheck" =\> "%{cycle\_time}"}  
convert =\> { "testcheck" =\> "string" }  
gsub =\> ["testcheck", "Z", ""]  
}

This is also not working.First of all date field not converting to string.

I don't required to log stash capture as date [field.Is](http://field.Is) there any way where i can tell log stash don't capture column as date field.If it capture cycle\_time as string field my problem will solve.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 18, 2017, 7:23am UTC](https://discuss.elastic.co/t/changing-time-zone-format/71775/8 "2017-01-18T07:23:26Z")

</div>

Oh, `cycle_time` is a date. Then I suggest you use a ruby filter to format the timestamp in any way you like and store in a different field.

I gave the same answer to the exact same question just a few hours ago. Either there are two of you having the same problem at the same time or you posted the same question twice (please don't do that).

---

<div class="post-metadata">

**Author:** ![Dan](https://avatars.discourse-cdn.com/v4/letter/d/eada6e/32.png) [@Dan](https://discuss.elastic.co/u/Dan)\
**Post date:** [January 18, 2017, 7:55am UTC](https://discuss.elastic.co/t/changing-time-zone-format/71775/9 "2017-01-18T07:55:16Z")

</div>

Thanks for your quick reply...

> [@magnusbaeck](#):
>
> I gave the same answer to the exact same question just a few hours ago. Either there are two of you having the same problem at the same time or you posted the same question twice (please don't do that).

I am not aware of this.

Can you please give me example to use ruby filter to convert time format.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 18, 2017, 8:15am UTC](https://discuss.elastic.co/t/changing-time-zone-format/71775/10 "2017-01-18T08:15:00Z")

</div>

Sorry, I don't have an example.

---

<div class="post-metadata">

**Author:** ![Dan](https://avatars.discourse-cdn.com/v4/letter/d/eada6e/32.png) [@Dan](https://discuss.elastic.co/u/Dan)\
**Post date:** [January 20, 2017, 4:24am UTC](https://discuss.elastic.co/t/changing-time-zone-format/71775/11 "2017-01-20T04:24:23Z")

</div>

I am still stuck in this issue.

I tried bellow ruby filter but its not working.

filter {  
ruby {  
code =\> "event['cycle\_time'] = event['cycle\_time'].localtime('+02:00')"  
}  
}

Please help me how can solve....

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 20, 2017, 6:28am UTC](https://discuss.elastic.co/t/changing-time-zone-format/71775/12 "2017-01-20T06:28:36Z")

</div>

What does "it's not working" mean? Do you get incorrect results? Or nothing happens at all? Any error message in Logstash's log?

---

<div class="post-metadata">

**Author:** ![Dan](https://avatars.discourse-cdn.com/v4/letter/d/eada6e/32.png) [@Dan](https://discuss.elastic.co/u/Dan)\
**Post date:** [January 20, 2017, 8:12am UTC](https://discuss.elastic.co/t/changing-time-zone-format/71775/13 "2017-01-20T08:12:04Z")

</div>

nothing happening....  
even i am not getting any error as well...

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 20, 2017, 8:22am UTC](https://discuss.elastic.co/t/changing-time-zone-format/71775/14 "2017-01-20T08:22:26Z")

</div>

Please comment out the ruby filter and show us what the event looks like. Use a `stdout { codec => rubydebug }` output.

---

<div class="post-metadata">

**Author:** ![Dan](https://avatars.discourse-cdn.com/v4/letter/d/eada6e/32.png) [@Dan](https://discuss.elastic.co/u/Dan)\
**Post date:** [January 20, 2017, 9:11am UTC](https://discuss.elastic.co/t/changing-time-zone-format/71775/15 "2017-01-20T09:11:50Z")

</div>

i am getting bellow error when i add [quote="magnusbaeck, post:14, topic:71775"]  
stdout { codec =\> rubydebug }  
[/quote]

[2017-01-20T14:37:02,553][ERROR][logstash.filters.ruby] Ruby exception occurred: Direct event field references (i.e. event['field']) have been disabled in favor of using event get and set methods (e.g. event.get('field')). Please consult the Logstash 5.0 breaking changes documentation for more details.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 20, 2017, 9:23am UTC](https://discuss.elastic.co/t/changing-time-zone-format/71775/16 "2017-01-20T09:23:10Z")

</div>

Aha, right. So did you read the documentation the error message points you to?

This piece of Ruby will work better:

```
event.set('cycle_time', event.get('cycle_time').localtime('+02:00'))
```

---

<div class="post-metadata">

**Author:** ![Dan](https://avatars.discourse-cdn.com/v4/letter/d/eada6e/32.png) [@Dan](https://discuss.elastic.co/u/Dan)\
**Post date:** [January 20, 2017, 10:22am UTC](https://discuss.elastic.co/t/changing-time-zone-format/71775/17 "2017-01-20T10:22:39Z")

</div>

Getting below error

[2017-01-20T14:56:02,576][ERROR][logstash.filters.ruby] Ruby exception occurred: undefined method `localtime' for 2017-01-07T03:30:07.000Z:LogStash::Timestamp

doc and my system time zone both are same.

> [@Ruby exception occurred: undefined method \`localtime'](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-localtime/48751):
>
> hi all, I am using logstash 2.1.3 ,I want to show the @timestamp field in my timezone, like "@timestamp" =\> "2015-03-09T04:24:29.718+08:00", I try to using ruby conversion in filter. filter { ruby { code =\> "event['@timestamp'] = event['@timestamp'].localtime('+08:00')" } } but i got the error msg as below, Ruby exception occurred: undefined method `localtime' for "2016-04-29T00:40:51.926Z":LogStash::Timestamp {:level=\>:error} Any help is welcome to resolve this.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 20, 2017, 10:43am UTC](https://discuss.elastic.co/t/changing-time-zone-format/71775/18 "2017-01-20T10:43:15Z")

</div>

Okay. Then my suggestion is this:

```
event.set('cycle_time', event.get('cycle_time').time.localtime('+02:00'))
```

---

<div class="post-metadata">

**Author:** ![Dan](https://avatars.discourse-cdn.com/v4/letter/d/eada6e/32.png) [@Dan](https://discuss.elastic.co/u/Dan)\
**Post date:** [January 20, 2017, 11:12am UTC](https://discuss.elastic.co/t/changing-time-zone-format/71775/19 "2017-01-20T11:12:26Z")

</div>

Thanks for your quick reply...

I am getting bellow error

**Ruby exception occurred: undefined method `time' for nil:NilClass**

using below filter  
ruby {  
code =\> "event.set('cycle\_time', event.get('cycle\_time').time.localtime('+02:00'))"  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 20, 2017, 11:52am UTC](https://discuss.elastic.co/t/changing-time-zone-format/71775/20 "2017-01-20T11:52:02Z")

</div>

That indicates that you tried to use that ruby filter for an event that didn't have a `cycle_time` field. One way of mitigating that would be:

```
event.set('cycle_time', event.get('cycle_time').time.localtime('+02:00')) unless event.get('cycle_time').nil?
```

[Next page](https://discuss.elastic.co/t/changing-time-zone-format/71775.md?page=2)
