# Convert Timestamp in Elasticsearch Query Rule

**URL:** <https://discuss.elastic.co/t/convert-timestamp-in-elasticsearch-query-rule/297297>\
**Category:** Elastic Observability\
**Tags:** elastic-stack-alerting\
**Created:** [February 15, 2022, 9:16pm UTC](https://discuss.elastic.co/t/convert-timestamp-in-elasticsearch-query-rule/297297 "2022-02-15T21:16:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jdwinns](https://avatars.discourse-cdn.com/v4/letter/j/71e660/32.png) [@jdwinns](https://discuss.elastic.co/u/jdwinns)\
**Post date:** [February 15, 2022, 9:16pm UTC](https://discuss.elastic.co/t/convert-timestamp-in-elasticsearch-query-rule/297297/1 "2022-02-15T21:16:51Z")

</div>

Hi folks,

I am new to the ELK stack and have a question in regards to an Elastic query rule and e-mail alert that I've created.

Currently, I am including the log @timestamp field in the e-mail alert using this variable:  
**{{context.hits.0.\_source.@timestamp}}**

The @timestamp field in the alert is coming through in **UTC** and I need it formatted in **EST**. Is there any way to modify/convert the timestamp at the query level and output the results to an alert?

Here is the Elasticsearch query that I'm currently using:

```auto
{
  "query": {
    "bool": {
      "must": [],
      "filter": [
        {
          "match_phrase": {
            "message": "Caused by: java.net.ConnectException"
          }
        },
        {
          "match_phrase": {
            "path": "C:\\Path\\To\\Error.log"
          }
        },
        {
          "match_phrase": {
            "level": "ERROR"
          }
        }
        ]
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Patrick\_Mueller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_mueller/32/109425_2.png) [@Patrick\_Mueller](https://discuss.elastic.co/u/Patrick_Mueller)\
**Post date:** [February 15, 2022, 9:37pm UTC](https://discuss.elastic.co/t/convert-timestamp-in-elasticsearch-query-rule/297297/2 "2022-02-15T21:37:18Z")

</div>

> [@jdwinns](#):
>
> The @timestamp field in the alert is coming through in **UTC** and I need it formatted in **EST**. Is there any way to modify/convert the timestamp at the query level and output the results to an alert?

Not currently, but we have an issue open to allow this sort of thing, with time formatting being one of the use cases. [https://github.com/elastic/kibana/issues/84217](https://github.com/elastic/kibana/issues/84217)

Feel free to comment there how well this would work for your use case, so you can follow along when we start working on an implementation.

There's also a proof-of-concept PR where we're playing with some of this, to show you some examples of how this would actually work: [[actions] add mustache lambdas for use in action templates by pmuellr · Pull Request #107612 · elastic/kibana · GitHub](https://github.com/elastic/kibana/pull/107612/files#diff-581e58ef64d09b18644226563ab228ea23265376571aa16fb3f37f7ddbb1c45dR58-R98)

---

<div class="post-metadata">

**Author:** ![jdwinns](https://avatars.discourse-cdn.com/v4/letter/j/71e660/32.png) [@jdwinns](https://discuss.elastic.co/u/jdwinns)\
**Post date:** [February 16, 2022, 4:18pm UTC](https://discuss.elastic.co/t/convert-timestamp-in-elasticsearch-query-rule/297297/3 "2022-02-16T16:18:20Z")

</div>

Thank you @Patrick_Mueller, this is awesome! I just subscribed to the Git thread you shared and will definitely follow the development progress.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:34am UTC](https://discuss.elastic.co/t/convert-timestamp-in-elasticsearch-query-rule/297297/4 "2022-11-04T08:34:13Z")

</div>


