# Copying @timestamp in custom field not working

**URL:** <https://discuss.elastic.co/t/copying-timestamp-in-custom-field-not-working/33738>\
**Category:** Logstash\
**Created:** [November 4, 2015, 12:27pm UTC](https://discuss.elastic.co/t/copying-timestamp-in-custom-field-not-working/33738 "2015-11-04T12:27:03Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [November 4, 2015, 12:27pm UTC](https://discuss.elastic.co/t/copying-timestamp-in-custom-field-not-working/33738/1 "2015-11-04T12:27:03Z")

</div>

Hi,  
I am trying to copy the timestamp field in logs to some custom field 'eventLogTime' on Kibana. This I want to use for sorting on basis of event time.

I am using below configuration in logstash indexer

```
grok {
                 match => { "message" => "%{TIMESTAMP_ISO8601:eventLogTime}" }
                 add_field => ["eventLogTime", "%{eventLogTime}"]
         }
        date {
                 match => ["eventLogTime", "YYYY-MM-dd'T'HH:mm:ss", "YYYY-MM-dd HH:mm:ss","HH:mm:ss MMM dd yyyy","YYYY-MM-dd HH:mm:ss,SSS","yyyy.MM.dd G 'at' HH:mm:ss z","yyyyy.MMMMM.dd GGG hh:mm aaa","EEE, d MMM yyyy HH:mm:ss Z","yyyy-MM-dd'T'HH:mm:ss.SSSZ","yyyy-MM-dd'T'HH:mm:ss.SSSZ+0300", "YYYY/MM/dd HH:mm:ss","yyyy-MM-dd'T'HH:mm:ss.SSSSSZ+03:00"]
        target => "eventLogTime"

```

However I ma not getting expected result.

Log line is

```
 2015-11-04 14:22:04,598 username:'' INFO [DepartureProgressLoaderJob: 41] - DepartureProgressLoaderJob loaded: 0 departures in 228ms

```

I am expecting **2015-11-04 14:22:04,598** under the field evenLogTime on Kibana. But the time shown under eventLogTime is **November 4th 2015, 17:52:04.598**. Notice the time difference which is exactly equal to the difference in EET and IST.

Please let me know what is wrong with my filter.

thanks  
Sunil Chaudhari.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 4, 2015, 7:17pm UTC](https://discuss.elastic.co/t/copying-timestamp-in-custom-field-not-working/33738/2 "2015-11-04T19:17:01Z")

</div>

> add\_field =\> ["eventLogTime", "%{eventLogTime}"]

This doesn't make sense. You're assigning a field to itself. Remove.

> I am expecting 2015-11-04 14:22:04,598 under the field evenLogTime on Kibana. But the time shown under eventLogTime is November 4th 2015, 17:52:04.598 . Notice the time difference which is exactly equal to the difference in EET and IST.

The date filter converts timestamps to UTC for storage in Elasticsearch and Kibana then adjusts UTC timestamps to the browser's timezone. This is by design and is currently not configurable.

---

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [November 5, 2015, 5:08am UTC](https://discuss.elastic.co/t/copying-timestamp-in-custom-field-not-working/33738/3 "2015-11-05T05:08:58Z")

</div>

Thanks Magnus,

Is there anyway to copy timestamp (in the log) to customized field. And then I will use that new time field instead of @timestamp for time filter.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 5, 2015, 6:36am UTC](https://discuss.elastic.co/t/copying-timestamp-in-custom-field-not-working/33738/4 "2015-11-05T06:36:17Z")

</div>

Sorry, not following. How is what you describe different from what you're already doing? You parse the message to extract an `eventLogTime` field, and parse that into an ISO8601 timestamp.

If you want your timestamp field as used in Kibana to be named anything but `@timestamp` you have to make sure you map that field as a timestamp. If you look at the existing index template I think it'll be obvious what you need to do.

---

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [November 5, 2015, 6:40am UTC](https://discuss.elastic.co/t/copying-timestamp-in-custom-field-not-working/33738/5 "2015-11-05T06:40:46Z")

</div>

Hi Magnu,  
Thanks. Now its clear.

I didnt read your last comment carefully. "Kibana then adjusts UTC timestamps to the browser's timezone"  
My mistake.

I am doing exactly what I want, but I was confused because I am accessing Kibana in IST zone. In production it will be accessed from EET. so No issue. 😄

Thanks,  
Sunil.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:23am UTC](https://discuss.elastic.co/t/copying-timestamp-in-custom-field-not-working/33738/6 "2017-07-06T05:23:57Z")

</div>


