# Convert utc format to local time

**URL:** <https://discuss.elastic.co/t/convert-utc-format-to-local-time/164237>\
**Category:** Logstash\
**Created:** [January 15, 2019, 5:14am UTC](https://discuss.elastic.co/t/convert-utc-format-to-local-time/164237 "2019-01-15T05:14:44Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![wangqinghuan](https://avatars.discourse-cdn.com/v4/letter/w/d26b3c/32.png) [@wangqinghuan](https://discuss.elastic.co/u/wangqinghuan)\
**Post date:** [January 15, 2019, 5:14am UTC](https://discuss.elastic.co/t/convert-utc-format-to-local-time/164237/1 "2019-01-15T05:14:44Z")

</div>

hi  
I am using logstash to output data from elasticsearch to file. A field named 'snapTime' in elasticsearch is represented by utc format '2018-09-10T15:05:43.000Z' and logstash outputs this field in utc format to file too. Now I want to convert utc format to local time(China), e.g, convert '2018-09-10T15:05:43.000Z' to '2018-09-10 23:05:43' and output it to file. It seems like ruby can make efforts, I try some scripts as follows:  
`
filter{
ruby{
code => "event.set('snapTime',event.get('snapTime').localtime('+08:00'))"
}
}
`  
Then an exception occurs as  
`'Ruby exception occurred: undefined method `localtime' for "2019-01-10T02:39:12.000Z":String'. `  
Obviously event.get('snapTime') gives a string not a time. How to implement convertion from utc to local in logstash? thank you

---

<div class="post-metadata">

**Author:** ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)\
**Post date:** [January 15, 2019, 7:02am UTC](https://discuss.elastic.co/t/convert-utc-format-to-local-time/164237/2 "2019-01-15T07:02:55Z")

</div>

I think you need to import Time class in order to use it's methods. Also, as you said, you have to parse the string into a Time-class instance.  
Try something like this:

```
filter {
  ruby {
    init => 'require "time"'
    code => 'event.set("snapTime", Time.parse(event.get("snapTime")).localtime("+08:00"))'
  }
}
```

---

<div class="post-metadata">

**Author:** ![wangqinghuan](https://avatars.discourse-cdn.com/v4/letter/w/d26b3c/32.png) [@wangqinghuan](https://discuss.elastic.co/u/wangqinghuan)\
**Post date:** [January 15, 2019, 7:37am UTC](https://discuss.elastic.co/t/convert-utc-format-to-local-time/164237/3 "2019-01-15T07:37:33Z")

</div>

> [@admlko](#):
>
> init =\> 'require "time"'

thank you. I have tried as your said. Athough no exception happens, the 'snapTime' filed still retainutc format rather than my local time zone.  
The filter as follows:  
`
filter{
ruby{
init => 'require "time"'
code => "event.set('snapTime',Time.parse(event.get('snapTime')).localtime('+08:00'))"
}
}
`  
The rubydebug stdout as follows:  
{  
"snapTime" =\> 2019-01-10T02:39:12.000Z,  
"@version" =\> "1",  
"@timestamp" =\> 2019-01-15T07:22:59.390Z,  
"name" =\> "wangqh"  
}  
the field 'snapTime' still retain '2019-01-10T02:39:12.000Z' rather than '2019-01-10T10:39:12.000+08:00'

---

<div class="post-metadata">

**Author:** ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)\
**Post date:** [January 15, 2019, 7:44am UTC](https://discuss.elastic.co/t/convert-utc-format-to-local-time/164237/4 "2019-01-15T07:44:03Z")

</div>

Yes of course it stays in ISO8601 format, because no line of that code changes it. If you want it in different format, you need to specify it, for example:

> Time.parse(event.get("snapTime")).localtime("+08:00")).strftime("%Y-%m-%d %H:%M:%S")

If this wasn't the case and I misunderstood your first post, I have to get more information.  
Could you give an example input line, and then try it with a simple pipeline, only stdin input, this as the only filter, and stdout rubyrebug in output.

---

<div class="post-metadata">

**Author:** ![wangqinghuan](https://avatars.discourse-cdn.com/v4/letter/w/d26b3c/32.png) [@wangqinghuan](https://discuss.elastic.co/u/wangqinghuan)\
**Post date:** [January 15, 2019, 8:21am UTC](https://discuss.elastic.co/t/convert-utc-format-to-local-time/164237/5 "2019-01-15T08:21:09Z")

</div>

It works after specify format. thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 12, 2019, 8:21am UTC](https://discuss.elastic.co/t/convert-utc-format-to-local-time/164237/6 "2019-02-12T08:21:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
