# Convert Elasticsearch Date/Time field from UTC To Local Time

**URL:** <https://discuss.elastic.co/t/convert-elasticsearch-date-time-field-from-utc-to-local-time/191070>\
**Category:** Logstash\
**Created:** [July 17, 2019, 6:10pm UTC](https://discuss.elastic.co/t/convert-elasticsearch-date-time-field-from-utc-to-local-time/191070 "2019-07-17T18:10:59Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [July 17, 2019, 6:10pm UTC](https://discuss.elastic.co/t/convert-elasticsearch-date-time-field-from-utc-to-local-time/191070/1 "2019-07-17T18:10:59Z")

</div>

I am query elasticsearch in my pipeline for a date/time field. Elasticsearch stores those date/time fields in UTC time, regardless of of the timezone they were ingested in. Is it possible to convert the time to local time?

Alternatively, can I take a local time value and convert it to utc? I'm using the two values to compare the time difference between them so I need them to be in the same zone.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 17, 2019, 6:14pm UTC](https://discuss.elastic.co/t/convert-elasticsearch-date-time-field-from-utc-to-local-time/191070/2 "2019-07-17T18:14:56Z")

</div>

[Tell](https://discuss.elastic.co/t/timezone-causing-problem-when-doing-a-search-query-to-an-index/61077/2) elasticsearch what timezone you want the results to be in as part of the query?

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [July 17, 2019, 6:28pm UTC](https://discuss.elastic.co/t/convert-elasticsearch-date-time-field-from-utc-to-local-time/191070/3 "2019-07-17T18:28:32Z")

</div>

How do I do that? I see in the documentation I would use the `time_zone` parameter but where and how exactly? Do I have to use a query template or can I stick to using a query string?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 17, 2019, 6:32pm UTC](https://discuss.elastic.co/t/convert-elasticsearch-date-time-field-from-utc-to-local-time/191070/4 "2019-07-17T18:32:44Z")

</div>

There is an example in the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-range-query.html#range-query-time-zone). I do not think you are forced to use a template.

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [July 17, 2019, 6:50pm UTC](https://discuss.elastic.co/t/convert-elasticsearch-date-time-field-from-utc-to-local-time/191070/5 "2019-07-17T18:50:51Z")

</div>

Wait, let me back up, I think I went down the wrong rabbit hole. I am performing an elasticsearch query looking for a ticket number, say `abc123`. If that ticket number is found, then give me the field, `updated_on`, which is a date field stored in UTC time.

My understanding of what you are saying for me to do would not work because it assumes I am querying for a field value that is a date/time field, which I am not.

Or am I still misunderstanding and there is a way to have the requested fields returned in local time?

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [July 17, 2019, 6:53pm UTC](https://discuss.elastic.co/t/convert-elasticsearch-date-time-field-from-utc-to-local-time/191070/6 "2019-07-17T18:53:39Z")

</div>

Here's my query config, if it helps:

```auto
  elasticsearch {
    hosts => ["https://fqdn:9200"]
   #The number field has an alphanumeric value.
    query => "number:%{number}"
    index => "servicenow-*"
   #The sys_updated_on field has a date/time value.
    fields => { "sys_updated_on" => "[old][sys_updated]" }
  }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 17, 2019, 6:55pm UTC](https://discuss.elastic.co/t/convert-elasticsearch-date-time-field-from-utc-to-local-time/191070/7 "2019-07-17T18:55:41Z")

</div>

Oh, right. In that case I would mutate+convert it to a string and run it through a date filter with a timezone option. It's not elegant, but it should work.

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [July 17, 2019, 7:15pm UTC](https://discuss.elastic.co/t/convert-elasticsearch-date-time-field-from-utc-to-local-time/191070/8 "2019-07-17T19:15:01Z")

</div>

The value returned by elasticsearch is a date/time string, so I can't directly convert it (When I do, all I get is `2019`). I can pass it to the date filter to convert it to a date/time object, then run a ruby code that converts it to unix time, but I'm still 5-6 hours off, depending on daylight savings time.

```auto
    #Convert elasticsearch returned string value into date/time data type
    date {
      match => ["[old][sys_updated]", "yyyy-MM-dd'T'HH:mm:ss.SSS'Z'" ]
      target => "[old][sys_updated_time]"
    }
    #Convert date/time data type value into epoch seconds
    ruby { 
      code => 'event.set("[old][sys_updated_epoch]", event.get("[old][sys_updated_time]").to_i)'
    }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 17, 2019, 7:18pm UTC](https://discuss.elastic.co/t/convert-elasticsearch-date-time-field-from-utc-to-local-time/191070/9 "2019-07-17T19:18:49Z")

</div>

Strip off the Z with mutate+gsub before passing to a date filter with a timezone option?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 14, 2019, 7:18pm UTC](https://discuss.elastic.co/t/convert-elasticsearch-date-time-field-from-utc-to-local-time/191070/10 "2019-08-14T19:18:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
