# Convert NanoSecond Unix timestamp

**URL:** https://discuss.elastic.co/t/convert-nanosecond-unix-timestamp/324368
**Category:** Logstash
**Created:** [January 31, 2023, 8:34pm UTC](https://discuss.elastic.co/t/convert-nanosecond-unix-timestamp/324368 "2023-01-31T20:34:55Z")
**Posts on this page:** 10
**Page:** 1

<div class="post-metadata">

### Author: ![maskrider1111](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maskrider1111/32/116613_2.png) [@maskrider1111](https://discuss.elastic.co/u/maskrider1111)
#### Post date: [January 31, 2023, 8:34pm UTC](https://discuss.elastic.co/t/convert-nanosecond-unix-timestamp/324368/1 "2023-01-31T20:34:55Z")

</div>

Hi Folks,

Any idea how to convert the nanosecond unix timestamp in logstash filter?

```auto
date {
                match => ["eventtime","UNIX_MS", "ISO8601"]
                target => "Epoch"
                timezone => "UTC"
                }

```

Apparently its not working

```auto
 "Epoch" => +53023221-08-28T18:34:21.798Z,

```

---

<div class="post-metadata">

### Author: ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)
#### Post date: [January 31, 2023, 8:43pm UTC](https://discuss.elastic.co/t/convert-nanosecond-unix-timestamp/324368/2 "2023-01-31T20:43:11Z")

</div>

Welcome to the community Jay.  
Can you explain what are first 8 digits?  
"Epoch" =\> + **53023221** -08-28T18:34:21.798Z

Or show the eventtime field value.

---

<div class="post-metadata">

### Author: ![maskrider1111](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maskrider1111/32/116613_2.png) [@maskrider1111](https://discuss.elastic.co/u/maskrider1111)
#### Post date: [January 31, 2023, 9:08pm UTC](https://discuss.elastic.co/t/convert-nanosecond-unix-timestamp/324368/3 "2023-01-31T21:08:52Z")

</div>

Thanks @Rios.

This is the another example of the eventtime field value:

```auto
eventtime: 1673188498490039856
Target "Epoch": +53023202-10-20T09:53:59.856Z

```

I understand that UNIX\_MS (milisecond) plugin will not work on nanoseconds timestamp. Any work around?

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [January 31, 2023, 9:18pm UTC](https://discuss.elastic.co/t/convert-nanosecond-unix-timestamp/324368/4 "2023-01-31T21:18:58Z")

</div>

> [@Rios](#):
>
> Can you explain what are first 8 digits?  
> "Epoch" =\> + **53023221** -08-28T18:34:21.798Z

It is 53 million years in the future.

The simplest solution is to throw away all the sub-millisecond precision.

```
    mutate { add_field => { "eventtime" => 1675199470000000000 } }
    mutate { gsub => ["eventtime", "\d{6}$", ""] }
    date { match => ["eventtime","UNIX_MS", "ISO8601"] target => "Epoch" timezone => "UTC" }

```

gives you

```
     "Epoch" => 2023-01-31T21:11:10.000Z

```

---

<div class="post-metadata">

### Author: ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)
#### Post date: [January 31, 2023, 9:25pm UTC](https://discuss.elastic.co/t/convert-nanosecond-unix-timestamp/324368/5 "2023-01-31T21:25:04Z")

</div>

Proof how LS is advance 🙂  
Use the simplest solution. If nanosec is mandatory in ES, then use [this](https://discuss.elastic.co/t/how-to-index-nanoseconds-precision-events-with-logstash-7-10-and-type-date-nanos/262029) or [this](https://github.com/elastic/logstash/issues/10822)

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [January 31, 2023, 9:37pm UTC](https://discuss.elastic.co/t/convert-nanosecond-unix-timestamp/324368/6 "2023-01-31T21:37:02Z")

</div>

> [@Badger](#):
>
> The simplest solution is to throw away all the sub-millisecond precision.

If you need nanosecond precision it can be done in logstash

```
    mutate { add_field => { "eventtime" => 1675199470123456789 } }
    ruby {
        code => '
            n = event.get("eventtime")
            if n
                match = /(\d+)(\d{9})/.match(n)
                event.set("@timestamp", LogStash::Timestamp.new(Time.at(match[1].to_i, match[2].to_i, :nsec)))
            end
        '
    }

```

will produce

```
"@timestamp" => 2023-01-31T21:11:10.123456789Z,

```

---

<div class="post-metadata">

### Author: ![maskrider1111](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maskrider1111/32/116613_2.png) [@maskrider1111](https://discuss.elastic.co/u/maskrider1111)
#### Post date: [January 31, 2023, 9:39pm UTC](https://discuss.elastic.co/t/convert-nanosecond-unix-timestamp/324368/7 "2023-01-31T21:39:42Z")

</div>

Hi @Badger ,

Sorry im not an expert when its comes to logstash filtering. Your solution seems to work but logstash unable to parse the date. Did i miss anything here?

![image](https://us1.discourse-cdn.com/elastic/original/3X/5/7/5717b08c65f98976504e66a0a7228dbefb45ffee.png)

![image](https://us1.discourse-cdn.com/elastic/original/3X/3/b/3b1165b460424f59a980be570d80aad33c261fe2.png)

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [January 31, 2023, 9:42pm UTC](https://discuss.elastic.co/t/convert-nanosecond-unix-timestamp/324368/8 "2023-01-31T21:42:16Z")

</div>

Your eventtime is an array, so you would need to use [eventtime][0] in the date filter. But if it is an array then you never should have gotten a far future date, so I am not sure what your data really looks like.

---

<div class="post-metadata">

### Author: ![maskrider1111](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maskrider1111/32/116613_2.png) [@maskrider1111](https://discuss.elastic.co/u/maskrider1111)
#### Post date: [January 31, 2023, 9:57pm UTC](https://discuss.elastic.co/t/convert-nanosecond-unix-timestamp/324368/9 "2023-01-31T21:57:29Z")

</div>

Awesome, its work. Thank you so much for the solution. You just solved the issue that I was struggling with for hours

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 28, 2023, 9:57pm UTC](https://discuss.elastic.co/t/convert-nanosecond-unix-timestamp/324368/10 "2023-02-28T21:57:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
