# Custom Date and Time Format

**URL:** <https://discuss.elastic.co/t/custom-date-and-time-format/104674>\
**Category:** Kibana\
**Created:** [October 20, 2017, 8:53am UTC](https://discuss.elastic.co/t/custom-date-and-time-format/104674 "2017-10-20T08:53:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![MaikLinnemann](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@MaikLinnemann](https://discuss.elastic.co/u/MaikLinnemann)\
**Post date:** [October 20, 2017, 8:53am UTC](https://discuss.elastic.co/t/custom-date-and-time-format/104674/1 "2017-10-20T08:53:03Z")

</div>

Hi there,

i have a configuration like:

grok {  
patterns\_dir =\> "/etc/logstash/patterns"  
match =\> ["message", "%{COMBINEDAPACHELOG}"]  
}

```
    date {
             match => ["timestamp", "dd/MMM/yyyy:HH:mm:ss Z"]
             target => "logdate"
       }
    
    date {
             match => ["timestamp", "dd/MMM/yyyy:HH:mm:ss Z"]
             target => "logtime"
       }   

```

What happens is that i can view the fields logdate and logtime in kibana, but not in a format that i need for further processing. what i can do to solve it, is to edit the fields in kibana to meet my requirements.

![grafik](https://us1.discourse-cdn.com/elastic/original/3X/2/9/29f7b517034b082d7c79f16c920b662d10686043.png)  
 ![grafik](https://us1.discourse-cdn.com/elastic/original/3X/f/0/f067ed2f1ccd7656690be11bbd9db61eceebde2d.png)

that works, so far so good. But what i want to know is how to solve that issue without editing the fields with kibana? I want to have those fields with the correct formatting directly delivered to elk/kibana.

any help is appreciated,

thanks,

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [October 23, 2017, 3:13pm UTC](https://discuss.elastic.co/t/custom-date-and-time-format/104674/2 "2017-10-23T15:13:59Z")

</div>

Hi Maik,

basically Elasticsearch stores them as type _date_ which internally is just a timestamp of milliseconds. So the way it is outputted is really a question of the visualization layer and you already figured out correctly how you can change that in Kibana. If you would want Elasticsearch to return you preformatted dates, you would need to store them as strings, but that means losing all the sorting, querying, visualizing, etc. capabilities on it like a date object.

In my opinion, there are not too many reasons, why you would want to store a meaningful date field (also) as a formatted string, instead of letting the actual output layer take care of that.

Cheers,  
Tim

---

<div class="post-metadata">

**Author:** ![MaikLinnemann](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@MaikLinnemann](https://discuss.elastic.co/u/MaikLinnemann)\
**Post date:** [October 24, 2017, 9:37am UTC](https://discuss.elastic.co/t/custom-date-and-time-format/104674/3 "2017-10-24T09:37:44Z")

</div>

Hi Tim,

i see what you mean and meanwhile i found a way to convert it to my needs in perl after it is stored in elastic as timestamp / date and not change it anywhere. Thanks for clarify.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 21, 2017, 9:37am UTC](https://discuss.elastic.co/t/custom-date-and-time-format/104674/4 "2017-11-21T09:37:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
