# Daily index rotation bug

**URL:** <https://discuss.elastic.co/t/daily-index-rotation-bug/161220>\
**Category:** Logstash\
**Created:** [December 17, 2018, 10:53pm UTC](https://discuss.elastic.co/t/daily-index-rotation-bug/161220 "2018-12-17T22:53:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![justinw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justinw/32/40277_2.png) [@justinw](https://discuss.elastic.co/u/justinw)\
**Post date:** [December 17, 2018, 10:53pm UTC](https://discuss.elastic.co/t/daily-index-rotation-bug/161220/1 "2018-12-17T22:53:38Z")

</div>

Hi,

Every now and then a few documents (less than 1% of total logs) get placed into a daily index where the `20` in `2018` is replaced by `00`.

For example,

`logstash-6.4.3-0018.12.08`

Has anyone encountered this? Seems like a bug somewhere, since all other docs get placed fine.

Best, Justin

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [December 18, 2018, 12:37am UTC](https://discuss.elastic.co/t/daily-index-rotation-bug/161220/2 "2018-12-18T00:37:29Z")

</div>

I'm guessing that you are including a sprintf statement that relies on the value of `@timestamp` in your declaration of which index to insert docs into (e.g., `index => "logstash-6.4.3-%{+yyyy.MM.dd}"`).

- what does the value of `@timestamp` indicate?
- If this is also showing years far in the past, how are you populating `@timestamp` (likely a `date` filter)?

---

<div class="post-metadata">

**Author:** ![justinw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justinw/32/40277_2.png) [@justinw](https://discuss.elastic.co/u/justinw)\
**Post date:** [December 18, 2018, 9:29pm UTC](https://discuss.elastic.co/t/daily-index-rotation-bug/161220/3 "2018-12-18T21:29:34Z")

</div>

Oh nice, good call. There's a date filter on nginx logs, and for these lines the date string is something like `18-12-08T01:34:06+00:00`.

Thanks @yaauie!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2019, 9:29pm UTC](https://discuss.elastic.co/t/daily-index-rotation-bug/161220/4 "2019-01-15T21:29:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
