# Converting TimeStamp to epoch in LogStash

**URL:** <https://discuss.elastic.co/t/converting-timestamp-to-epoch-in-logstash/243168>\
**Category:** Logstash\
**Created:** [July 30, 2020, 7:05am UTC](https://discuss.elastic.co/t/converting-timestamp-to-epoch-in-logstash/243168 "2020-07-30T07:05:17Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shanmuka\_Chowdary](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shanmuka_chowdary/32/73073_2.png) [@Shanmuka\_Chowdary](https://discuss.elastic.co/u/Shanmuka_Chowdary)\
**Post date:** [July 30, 2020, 7:05am UTC](https://discuss.elastic.co/t/converting-timestamp-to-epoch-in-logstash/243168/1 "2020-07-30T07:05:18Z")

</div>

Hi Team,  
I am trying to get some records from SQLServer through logstash.  
In the database the record is like this : `2002-09-03 04:00:00.000` ,  
But it's saving in elastic like : `"fileddate" : "2002-09-03T04:00:00.000Z"` without applying any filters.  
How can i convert this into EPOCH

---

<div class="post-metadata">

**Author:** ![Shanmuka\_Chowdary](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shanmuka_chowdary/32/73073_2.png) [@Shanmuka\_Chowdary](https://discuss.elastic.co/u/Shanmuka_Chowdary)\
**Post date:** [July 30, 2020, 10:24am UTC](https://discuss.elastic.co/t/converting-timestamp-to-epoch-in-logstash/243168/2 "2020-07-30T10:24:12Z")

</div>

@Jenni / @Christian_Dahlqvist / @warkolm Could you please help me on this

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [July 30, 2020, 10:49am UTC](https://discuss.elastic.co/t/converting-timestamp-to-epoch-in-logstash/243168/3 "2020-07-30T10:49:19Z")

</div>

It looks like you've got a Logstash Timestamp object/ Elasticsearch date field there, right? Do you want to have the seconds since 1970/01/01 00:00:00 as an integer or float instead? Then you can use the mutate filter to convert the timestamp. Or did you want something else?

---

<div class="post-metadata">

**Author:** ![Shanmuka\_Chowdary](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shanmuka_chowdary/32/73073_2.png) [@Shanmuka\_Chowdary](https://discuss.elastic.co/u/Shanmuka_Chowdary)\
**Post date:** [July 30, 2020, 11:03am UTC](https://discuss.elastic.co/t/converting-timestamp-to-epoch-in-logstash/243168/4 "2020-07-30T11:03:19Z")

</div>

Hi @Jenni.  
Yes it's a date field from SQL.  
I want to have my date field into integer (basically EPOCH) format into my index.  
How can i write the mutate filter.

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [July 30, 2020, 11:10am UTC](https://discuss.elastic.co/t/converting-timestamp-to-epoch-in-logstash/243168/5 "2020-07-30T11:10:19Z")

</div>

```auto
mutate {
  convert => { "fileddate" => "integer" }
}

```

---

<div class="post-metadata">

**Author:** ![Shanmuka\_Chowdary](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shanmuka_chowdary/32/73073_2.png) [@Shanmuka\_Chowdary](https://discuss.elastic.co/u/Shanmuka_Chowdary)\
**Post date:** [July 30, 2020, 11:41am UTC](https://discuss.elastic.co/t/converting-timestamp-to-epoch-in-logstash/243168/6 "2020-07-30T11:41:55Z")

</div>

Thank you,  
Integer is throwing an error, So i tried with long and it's working.  
The code is

```
      convert => {
        "fileddate" => "long"
      }

```

Now i'm trying to add another field for epoch and copying the data from **fileddate** and converting. But it's not working can you please tell me, where i'm going wrong.

```
mutate {
      add_field => {
        "epochtime" => "%{fileddate}"
      }
      convert => {
        "epochtime" => "long"
      }
    }
```

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [July 30, 2020, 11:49am UTC](https://discuss.elastic.co/t/converting-timestamp-to-epoch-in-logstash/243168/7 "2020-07-30T11:49:55Z")

</div>

`add_field` is a common option that is executed when a filter has been successful. Therefore it is executed after every other option of the mutate filter. So the execution order for your code above is the opposite of what you expected and `convert` is called before the field exists. You'll have to split that into two mutate filters.

---

<div class="post-metadata">

**Author:** ![Shanmuka\_Chowdary](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shanmuka_chowdary/32/73073_2.png) [@Shanmuka\_Chowdary](https://discuss.elastic.co/u/Shanmuka_Chowdary)\
**Post date:** [July 30, 2020, 11:55am UTC](https://discuss.elastic.co/t/converting-timestamp-to-epoch-in-logstash/243168/8 "2020-07-30T11:55:26Z")

</div>

Now I'm Calling this Like you mentioned, still throwing error

```
filter {

    mutate {
      add_field => {
        "epochtime" => "%{fileddate}"
      }
    }

    mutate {
      convert => {
        "epochtime" => "long"
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [July 30, 2020, 12:04pm UTC](https://discuss.elastic.co/t/converting-timestamp-to-epoch-in-logstash/243168/9 "2020-07-30T12:04:24Z")

</div>

"throwing error" is a pretty unspecific statement. But I'd guess that it is because by using `%{…}` you created `epochtime` as string, not as a Timestamp, so it cannot be converted this way. Use `copy` instead of `add_field` to create the field with the correct data type.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 31, 2020, 12:22am UTC](https://discuss.elastic.co/t/converting-timestamp-to-epoch-in-logstash/243168/10 "2020-07-31T00:22:24Z")

</div>

Please don't ping people that aren't already part of a topic.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 28, 2020, 12:22am UTC](https://discuss.elastic.co/t/converting-timestamp-to-epoch-in-logstash/243168/11 "2020-08-28T00:22:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
