# Convert @timestamp date format

**URL:** <https://discuss.elastic.co/t/convert-timestamp-date-format/125966>\
**Category:** Logstash\
**Created:** [March 28, 2018, 3:46pm UTC](https://discuss.elastic.co/t/convert-timestamp-date-format/125966 "2018-03-28T15:46:30Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bhairavi](https://avatars.discourse-cdn.com/v4/letter/b/9fc29f/32.png) [@Bhairavi](https://discuss.elastic.co/u/Bhairavi)\
**Post date:** [March 28, 2018, 3:46pm UTC](https://discuss.elastic.co/t/convert-timestamp-date-format/125966/1 "2018-03-28T15:46:30Z")

</div>

Hi! This is the sample logs which I am trying to store in elasticsearch index.

```
Mar 26 08:48:21 ip-192-168-0-94 sshd[18576]: Received disconnect from 115.238.245.2: 11: [preauth]

```

I want to convert this date pattern to something like "2017-01-12T07:56:41+0000". This is the filter I am using to parse the date.

```
date {
match => ["date", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
  }

```

I can see that in my elasticsearch index @timestamp field is stored like this- "2018-03-18T19:50:42.000Z". How do I convert this @timestamp format to "2017-01-12T07:56:41+0000". I've tried using mutate filter but it didn't work.

```
mutate {
    replace => ["date", "yyyy-MM-dd'T'HH:mm:ssZ"]
}

```

It just replaced the value. I am stucked here, any help would be appreciated. Thanks!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 28, 2018, 3:57pm UTC](https://discuss.elastic.co/t/convert-timestamp-date-format/125966/2 "2018-03-28T15:57:01Z")

</div>

Are you saying you want @timestamp to be displayed in a different format? If so, why?

---

<div class="post-metadata">

**Author:** ![Bhairavi](https://avatars.discourse-cdn.com/v4/letter/b/9fc29f/32.png) [@Bhairavi](https://discuss.elastic.co/u/Bhairavi)\
**Post date:** [March 28, 2018, 4:01pm UTC](https://discuss.elastic.co/t/convert-timestamp-date-format/125966/3 "2018-03-28T16:01:02Z")

</div>

Yes, I want to change @timestamp in a different format because the time stored in other indexes are in "2017-01-12T07:56:41+0000" format and for the mapping purpose I want to store the same timestamp format across all of my indexes.  
I have also thought about updating the 'date' field with the new format but couldn't find the way of doing so.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 28, 2018, 5:26pm UTC](https://discuss.elastic.co/t/convert-timestamp-date-format/125966/4 "2018-03-28T17:26:23Z")

</div>

For the latter, this does what I think you want...

```auto
  mutate { add_field => { "datetime" => "%{@timestamp}" } }
  mutate { gsub => ["datetime", ".000Z$", "+0000"] }

```

---

<div class="post-metadata">

**Author:** ![Bhairavi](https://avatars.discourse-cdn.com/v4/letter/b/9fc29f/32.png) [@Bhairavi](https://discuss.elastic.co/u/Bhairavi)\
**Post date:** [March 28, 2018, 6:43pm UTC](https://discuss.elastic.co/t/convert-timestamp-date-format/125966/5 "2018-03-28T18:43:52Z")

</div>

This worked 🙂  
Thank you so much for the help.

---

<div class="post-metadata">

**Author:** ![Bhairavi](https://avatars.discourse-cdn.com/v4/letter/b/9fc29f/32.png) [@Bhairavi](https://discuss.elastic.co/u/Bhairavi)\
**Post date:** [March 28, 2018, 10:20pm UTC](https://discuss.elastic.co/t/convert-timestamp-date-format/125966/6 "2018-03-28T22:20:14Z")

</div>

I have one doubt when I used this mutate filter to convert timestamp format in my local windows machine it worked properly and gave me time with +0000 format but, the same filter I've tried on my actual server which is an ubuntu machine & the datetime on kibana is still showed in 2018-03-28T22:12:37.472Z format. What could be the possible reason? Please help!

---

<div class="post-metadata">

**Author:** ![Bhairavi](https://avatars.discourse-cdn.com/v4/letter/b/9fc29f/32.png) [@Bhairavi](https://discuss.elastic.co/u/Bhairavi)\
**Post date:** [March 29, 2018, 3:39pm UTC](https://discuss.elastic.co/t/convert-timestamp-date-format/125966/7 "2018-03-29T15:39:20Z")

</div>

@Badger Is the timezone on which my machine is running could be the reason why mutate is not replacing the value of `datetime` field?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 29, 2018, 5:53pm UTC](https://discuss.elastic.co/t/convert-timestamp-date-format/125966/8 "2018-03-29T17:53:01Z")

</div>

Where are you getting fractional seconds from if you start with a date like "Mar 26 08:48:21"?

No matter. Change the gsub to

```auto
mutate { gsub => ["datetime", ".[0-9]{3}Z$", "+0000" ] }

```

---

<div class="post-metadata">

**Author:** ![Bhairavi](https://avatars.discourse-cdn.com/v4/letter/b/9fc29f/32.png) [@Bhairavi](https://discuss.elastic.co/u/Bhairavi)\
**Post date:** [March 29, 2018, 7:40pm UTC](https://discuss.elastic.co/t/convert-timestamp-date-format/125966/9 "2018-03-29T19:40:36Z")

</div>

Appreciated the help. It worked 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2018, 7:40pm UTC](https://discuss.elastic.co/t/convert-timestamp-date-format/125966/10 "2018-04-26T19:40:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
