# Convert one filed from CSV column header to time stamp when loading csv to elasticsearch

**URL:** <https://discuss.elastic.co/t/convert-one-filed-from-csv-column-header-to-time-stamp-when-loading-csv-to-elasticsearch/67220>\
**Category:** Logstash\
**Created:** [November 25, 2016, 9:34pm UTC](https://discuss.elastic.co/t/convert-one-filed-from-csv-column-header-to-time-stamp-when-loading-csv-to-elasticsearch/67220 "2016-11-25T21:34:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![shilong](https://avatars.discourse-cdn.com/v4/letter/s/f07891/32.png) [@shilong](https://discuss.elastic.co/u/shilong)\
**Post date:** [November 25, 2016, 9:34pm UTC](https://discuss.elastic.co/t/convert-one-filed-from-csv-column-header-to-time-stamp-when-loading-csv-to-elasticsearch/67220/1 "2016-11-25T21:34:51Z")

</div>

no. count sub-category ranking date  
1 23 sd N 2016-10-23  
The above is a simple snippet for CSV data. I use logstash to ship the data to elasticsearch vis csv filter.  
I want to make date as the timestamp on elasticsearch, is it possible to do that? Thank you!

---

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [November 26, 2016, 4:36am UTC](https://discuss.elastic.co/t/convert-one-filed-from-csv-column-header-to-time-stamp-when-loading-csv-to-elasticsearch/67220/2 "2016-11-26T04:36:07Z")

</div>

HI @shilong, Yes it is possible, however your information only contains a date without any time?

Lets say your CSV has the following fields, e.g.:

> 1 23 sd N 2016-10-23  
> ......  
> Nr = 1  
> Events = 23  
> SD = sd  
> Direction = N  
> Date = 2016-10-23

Then here is an example of how you can convert this to a date the field `Date = 2016-10-23`:

> csv {  
> columns =\> [  
> "Nr",  
> "Events",  
> "SD",  
> "Direction",  
> "Date"  
> ]  
> separator =\> " "  
> remove\_field =\> ["message"]  
> }  
> date {  
> locale =\> "en"  
> match =\> ["Date", "YYYY-MM-dd", "ISO8601"]  
> timezone =\> "Africa/Windhoek"  
> target =\> "@timestamp"  
> add\_field =\> { "debug" =\> "timestampMatched"}  
> }

I hope this helps

---

<div class="post-metadata">

**Author:** ![shilong](https://avatars.discourse-cdn.com/v4/letter/s/f07891/32.png) [@shilong](https://discuss.elastic.co/u/shilong)\
**Post date:** [November 28, 2016, 5:02am UTC](https://discuss.elastic.co/t/convert-one-filed-from-csv-column-header-to-time-stamp-when-loading-csv-to-elasticsearch/67220/3 "2016-11-28T05:02:31Z")

</div>

Thanks @Hans  
It doesn't work out really.  
I am wondering if the data like @timestamp tends to be November 27th 2016, 20:54:52.157, not just date value like 2016-11-27.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2016, 5:02am UTC](https://discuss.elastic.co/t/convert-one-filed-from-csv-column-header-to-time-stamp-when-loading-csv-to-elasticsearch/67220/4 "2016-12-26T05:02:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
