# Convert UNIX epoch to local time

**URL:** <https://discuss.elastic.co/t/convert-unix-epoch-to-local-time/81754>\
**Category:** Logstash\
**Created:** [April 10, 2017, 7:08am UTC](https://discuss.elastic.co/t/convert-unix-epoch-to-local-time/81754 "2017-04-10T07:08:07Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mitabrev](https://avatars.discourse-cdn.com/v4/letter/m/a88e57/32.png) [@mitabrev](https://discuss.elastic.co/u/mitabrev)\
**Post date:** [April 10, 2017, 7:08am UTC](https://discuss.elastic.co/t/convert-unix-epoch-to-local-time/81754/1 "2017-04-10T07:08:07Z")

</div>

Hi,

Hope I'm in the right section and will form the right question.

So my situation. I'm using logstash+elasticsearch+kibana for parsin some logs, CSV.

Parsing works perfectly.

I've got two date fieds, submission\_time and delivery\_time.  
I matched the submission\_time value to @timestamp and also to the same field for more human readable value.

@timestamp works perfect, correct time zone. While the submission\_time and delivery\_time show the UTC time.  
How can I change the "type of field" to show my local time?

Currently my filter is something like that:

date  
{  
match =\> ["submission\_time","UNIX"]  
target =\> "submission\_time"  
}

date  
{  
match =\> ["delivery\_time","UNIX"]  
target =\> "delivery\_time"  
}

I've tried with addint the "timezone" field, but no success.

Can you help? 🙂

Thank you!  
Mario

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 10, 2017, 7:38am UTC](https://discuss.elastic.co/t/convert-unix-epoch-to-local-time/81754/2 "2017-04-10T07:38:36Z")

</div>

> I matched the submission\_time value to @timestamp and also to the same field for more human readable value.

Human readable where?

> @timestamp works perfect, correct time zone. While the submission\_time and delivery\_time show the UTC time.

Where?

What's the mapping of the `submission_time` and `delivery_time` fields?

---

<div class="post-metadata">

**Author:** ![mitabrev](https://avatars.discourse-cdn.com/v4/letter/m/a88e57/32.png) [@mitabrev](https://discuss.elastic.co/u/mitabrev)\
**Post date:** [April 10, 2017, 8:29am UTC](https://discuss.elastic.co/t/convert-unix-epoch-to-local-time/81754/3 "2017-04-10T08:29:20Z")

</div>

This is my filer in .conf file:

```
date {
match => ['submission_time', 'UNIX']
}

date {
match => ['submission_time', 'UNIX']
target => 'submission_time'
}

date {
match => ['delivery_time', 'UNIX']
target => 'delivery_time'
}

```

and my result:

@timestamp April 7th 2017, 18:33:59.000 \<-- OK  
submission\_time 2017-04-07T16:33:59.000Z  
delivery\_time 2017-04-07T16:33:59.000Z

2 hour difference. I'm guessing i need to to change type of field?

BR,  
Mario

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 10, 2017, 8:57am UTC](https://discuss.elastic.co/t/convert-unix-epoch-to-local-time/81754/4 "2017-04-10T08:57:13Z")

</div>

What are the mappings of the fields in Elasticsearch? Use ES's get mapping API.

---

<div class="post-metadata">

**Author:** ![mitabrev](https://avatars.discourse-cdn.com/v4/letter/m/a88e57/32.png) [@mitabrev](https://discuss.elastic.co/u/mitabrev)\
**Post date:** [April 10, 2017, 10:02am UTC](https://discuss.elastic.co/t/convert-unix-epoch-to-local-time/81754/5 "2017-04-10T10:02:25Z")

</div>

```
{
  "bkki-2017.04.07" : {
    "mappings" : {
      "logs" : {
        "submission_time" : {
          "full_name" : "submission_time",
          "mapping" : {
            "submission_time" : {
              "type" : "date"
            }
          }
        }
      }
    }
  }
}

  "bkki-2017.04.07" : {
    "mappings" : {
      "logs" : {
        "delivery_time" : {
          "full_name" : "delivery_time",
          "mapping" : {
            "delivery_time" : {
              "type" : "date"
            }
          }
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 10, 2017, 11:45am UTC](https://discuss.elastic.co/t/convert-unix-epoch-to-local-time/81754/6 "2017-04-10T11:45:17Z")

</div>

That's surprising. I thought Kibana formatted all timestamps and not just `@timestamp`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2017, 11:51am UTC](https://discuss.elastic.co/t/convert-unix-epoch-to-local-time/81754/7 "2017-05-08T11:51:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
