# Convert Ticks to @timestamp in logstash with Ruby-plugin

**URL:** <https://discuss.elastic.co/t/convert-ticks-to-timestamp-in-logstash-with-ruby-plugin/58457>\
**Category:** Logstash\
**Created:** [August 19, 2016, 12:57pm UTC](https://discuss.elastic.co/t/convert-ticks-to-timestamp-in-logstash-with-ruby-plugin/58457 "2016-08-19T12:57:06Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![cvanhalt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cvanhalt/32/21745_2.png) [@cvanhalt](https://discuss.elastic.co/u/cvanhalt)\
**Post date:** [August 19, 2016, 12:57pm UTC](https://discuss.elastic.co/t/convert-ticks-to-timestamp-in-logstash-with-ruby-plugin/58457/1 "2016-08-19T12:57:06Z")

</div>

I query every minute against a MSSQL Database with jdbc-plugin.  
In this Database my timestamp is stored in ticks. Field-name is lastupdate.  
Now I wanted to convert the lastupdate field to a timestamp-format and then overwrite the @timestamp field with the converted lastvalue field.  
I tried the ruby filter-plugin, but couldn't achieve the conversion and instead got \_rubyexception and \_dateparsefailure.

My filter looks like this:

```
filter {
  if [type] == "mydb" {
    ruby {
      init => "require 'time'"
      code => "lastupdate = Time.at(event['lastupdate'].to_s)"
    }
    date {
      match => ["lastupdate", "MM/dd/YY HH:mm:ss,SSS"]
    }
  }
}

```

Thanks in advance!  
Chris

---

<div class="post-metadata">

**Author:** ![cvanhalt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cvanhalt/32/21745_2.png) [@cvanhalt](https://discuss.elastic.co/u/cvanhalt)\
**Post date:** [August 19, 2016, 2:09pm UTC](https://discuss.elastic.co/t/convert-ticks-to-timestamp-in-logstash-with-ruby-plugin/58457/2 "2016-08-19T14:09:26Z")

</div>

Solution:

[http://stackoverflow.com/questions/39039357/convert-ticks-to-timestamp-in-logstash-with-ruby-plugin](http://stackoverflow.com/questions/39039357/convert-ticks-to-timestamp-in-logstash-with-ruby-plugin)

```
filter {
  if [type] == "mydb" {
    ruby {
      code => "event['@timestamp'] = LogStash::Timestamp.at((event['lastupdate'].to_i - 621355968000000000) / 10_000_000.0)"
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 20, 2016, 7:28am UTC](https://discuss.elastic.co/t/convert-ticks-to-timestamp-in-logstash-with-ruby-plugin/58457/3 "2016-08-20T07:28:57Z")

</div>

Thanks for sharing the solution 🙂

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 20, 2016, 8:34pm UTC](https://discuss.elastic.co/t/convert-ticks-to-timestamp-in-logstash-with-ruby-plugin/58457/4 "2016-08-20T20:34:25Z")

</div>

Ticks is milliseconds since 1970-01-01, no? If so the date filter's UNIX\_MS pattern should be usable out of the box.

---

<div class="post-metadata">

**Author:** ![cvanhalt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cvanhalt/32/21745_2.png) [@cvanhalt](https://discuss.elastic.co/u/cvanhalt)\
**Post date:** [August 20, 2016, 9:43pm UTC](https://discuss.elastic.co/t/convert-ticks-to-timestamp-in-logstash-with-ruby-plugin/58457/5 "2016-08-20T21:43:25Z")

</div>

The value of this property represents the number of 100-nanosecond intervals that have elapsed since 12:00:00 midnight, January 1, 0001 (0:00:00 UTC on January 1, 0001, in the Gregorian calendar).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:42am UTC](https://discuss.elastic.co/t/convert-ticks-to-timestamp-in-logstash-with-ruby-plugin/58457/6 "2017-07-06T04:42:27Z")

</div>


