# Convert timestamp into date

**URL:** <https://discuss.elastic.co/t/convert-timestamp-into-date/187306>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-machine-learning\
**Created:** [June 25, 2019, 10:49am UTC](https://discuss.elastic.co/t/convert-timestamp-into-date/187306 "2019-06-25T10:49:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bharath\_Kumar\_R](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bharath_kumar_r/32/45474_2.png) [@Bharath\_Kumar\_R](https://discuss.elastic.co/u/Bharath_Kumar_R)\
**Post date:** [June 25, 2019, 10:49am UTC](https://discuss.elastic.co/t/convert-timestamp-into-date/187306/1 "2019-06-25T10:49:10Z")

</div>

I tried to extract anomaly results using the following request:

GET .ml-anomalies-.write-my\_job\_low\_sum/\_search?human  
{  
"size": 10000  
}

One of the results I got was:

"\_index" : ".ml-anomalies-custom-low\_sum\_results",  
"\_type" : "\_doc",  
"\_id" : "my\_job\_low\_sum\_record\_1560973500000\_900\_0\_275145719\_30",  
"\_score" : 8.38236,  
"\_source" : {  
"job\_id" : "my\_job\_low\_sum",  
"result\_type" : "record",  
"probability" : 6.795050328806717E-35,  
"multi\_bucket\_impact" : -5.0,  
"record\_score" : 79.66493,  
"initial\_record\_score" : 95.12116596413524,  
"bucket\_span" : 900,  
"detector\_index" : 0,  
"is\_interim" : false,  
"timestamp" : 1560973500000,  
...}  
Is it possible to internally convert the timestamp into date time ?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [June 25, 2019, 1:55pm UTC](https://discuss.elastic.co/t/convert-timestamp-into-date/187306/2 "2019-06-25T13:55:00Z")

</div>

You can use `script_fields` to access and modify the values. For example, something like this:

```auto
GET .ml-anomalies-*/_search
{
    "query": {
            "bool": {
              "filter": [
                  { "range" : { "timestamp" : { "gte": "now-5y" }}},
                  { "term" : { "job_id" : "farequote_responsetime" } },
                  { "term" : { "result_type" : "record" }},
                  { "range" : { "record_score" : { "gte": "75" }}}

              ]
            }
    },
    "script_fields": {
            "timestamp_iso8601": {
              "script": {
                  "lang": "painless",
                  "source": """doc["timestamp"]"""
                }
            },
            "record_score" : {
              "script": {
                  "lang": "painless",
                  "source": """Math.round(doc["record_score"].value)"""
              }
            },
            "airline" : {
              "script": {
                  "lang": "painless",
                  "source": """doc["partition_field_value"]"""
              }
            }
    }
}

```

The result would look something like:

```auto
{
  "took" : 12,
  "timed_out" : false,
  "_shards" : {
    "total" : 5,
    "successful" : 5,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 2,
      "relation" : "eq"
    },
    "max_score" : 0.0,
    "hits" : [
      {
        "_index" : ".ml-anomalies-shared",
        "_type" : "doc",
        "_id" : "farequote_responsetime_record_1486656000000_900_0_94347_3",
        "_score" : 0.0,
        "fields" : {
          "timestamp_iso8601" : [
            "2017-02-09T16:00:00.000Z"
          ],
          "airline" : [
            "AAL"
          ],
          "record_score" : [
            99
          ]
        }
      },
      {
        "_index" : ".ml-anomalies-shared",
        "_type" : "doc",
        "_id" : "farequote_responsetime_record_1486656900000_900_0_94347_3",
        "_score" : 0.0,
        "fields" : {
          "timestamp_iso8601" : [
            "2017-02-09T16:15:00.000Z"
          ],
          "airline" : [
            "AAL"
          ],
          "record_score" : [
            97
          ]
        }
      }
    ]
  }
}

```

---

<div class="post-metadata">

**Author:** ![Bharath\_Kumar\_R](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bharath_kumar_r/32/45474_2.png) [@Bharath\_Kumar\_R](https://discuss.elastic.co/u/Bharath_Kumar_R)\
**Post date:** [June 26, 2019, 8:24am UTC](https://discuss.elastic.co/t/convert-timestamp-into-date/187306/3 "2019-06-26T08:24:07Z")

</div>

will the date time be returned corresponding to my timezone?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [June 26, 2019, 12:00pm UTC](https://discuss.elastic.co/t/convert-timestamp-into-date/187306/4 "2019-06-26T12:00:35Z")

</div>

No, the fact that the timestamp has a `Z` at the end signifies that it is UTC. You can convert the timestamp into a local time using any Java-based method. For example:

```auto
            "timestamp_utc": {
              "script": {
                  "lang": "painless",
                  "source": """doc["timestamp"]"""
                }
            },
            "timestamp_local": {
              "script": {
                  "lang": "painless",
                  "source": """Instant.ofEpochMilli(doc["timestamp"].value.millis).atZone(ZoneOffset.ofHours(-5))"""
                }
            },

```

would yield:

```auto
          "timestamp_local" : [
            "2017-02-09T11:00:00.000-05:00"
          ],
          "timestamp_utc" : [
            "2017-02-09T16:00:00.000Z"
          ],

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2019, 12:00pm UTC](https://discuss.elastic.co/t/convert-timestamp-into-date/187306/5 "2019-07-24T12:00:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
