# Convert unix to standard date/time with milliseconds

**URL:** <https://discuss.elastic.co/t/convert-unix-to-standard-date-time-with-milliseconds/103411>\
**Category:** Logstash\
**Created:** [October 10, 2017, 5:09pm UTC](https://discuss.elastic.co/t/convert-unix-to-standard-date-time-with-milliseconds/103411 "2017-10-10T17:09:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tgdesrochers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tgdesrochers/32/51322_2.png) [@tgdesrochers](https://discuss.elastic.co/u/tgdesrochers)\
**Post date:** [October 10, 2017, 5:09pm UTC](https://discuss.elastic.co/t/convert-unix-to-standard-date-time-with-milliseconds/103411/1 "2017-10-10T17:09:00Z")

</div>

Elasticsearch 5.6  
Logstash 5.6

I have a log that is created with the below field:  
`unixTime: 1507655093`  
I am using the below logstash config to parse the date into the @timestamp field:  
`date { match => ["unixTime", "UNIX"] }`  
My result is returns a date formatted as:  
`2017-10-10T17:04:53.000Z`

What I expected was to get a date with the milliseconds included. Having all the events that could fire in a second all wrapped into the same timeframe is not ideal for log analysis.

Am I missing something simple to get logstash to output the Epoch with milliseconds?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [October 10, 2017, 6:24pm UTC](https://discuss.elastic.co/t/convert-unix-to-standard-date-time-with-milliseconds/103411/2 "2017-10-10T18:24:50Z")

</div>

It appears your `unixTime` field doesn't provide millisecond resolution. I pasted it at [https://www.epochconverter.com](https://www.epochconverter.com) and got: `GMT: Tuesday, October 10, 2017 5:04:53 PM`, exactly as you get from the `date` filter.

If your `unixTime` field value did provide millisecond resolution, you could use [`UNIX_MS`](https://www.elastic.co/guide/en/logstash/5.6/plugins-filters-date.html#plugins-filters-date-match) instead of `UNIX`, and it would capture the milliseconds.

---

<div class="post-metadata">

**Author:** ![tgdesrochers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tgdesrochers/32/51322_2.png) [@tgdesrochers](https://discuss.elastic.co/u/tgdesrochers)\
**Post date:** [October 10, 2017, 10:10pm UTC](https://discuss.elastic.co/t/convert-unix-to-standard-date-time-with-milliseconds/103411/3 "2017-10-10T22:10:07Z")

</div>

Thank you. I will try to get the application, osquery, to give me more  
granular times.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 7, 2017, 10:10pm UTC](https://discuss.elastic.co/t/convert-unix-to-standard-date-time-with-milliseconds/103411/4 "2017-11-07T22:10:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
