# Date, change day and month position

**URL:** <https://discuss.elastic.co/t/date-change-day-and-month-position/221606>\
**Category:** Logstash\
**Created:** [March 2, 2020, 1:05am UTC](https://discuss.elastic.co/t/date-change-day-and-month-position/221606 "2020-03-02T01:05:51Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [March 2, 2020, 1:05am UTC](https://discuss.elastic.co/t/date-change-day-and-month-position/221606/1 "2020-03-02T01:05:51Z")

</div>

I have a field called "timeanddate" and I use it as timestamp.

```auto
date {
       match => ["timeanddate", "HH:mm:ss MM/dd/yyyy"]
       target => "@timestamp"
 }

```

But I want to change the order of the date and put the day first and then the month, how can I achieve this?

```auto
dd/MM/yyyy
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 2, 2020, 1:54pm UTC](https://discuss.elastic.co/t/date-change-day-and-month-position/221606/2 "2020-03-02T13:54:50Z")

</div>

If you want to change the format in kibana then kibana lets you do that. If you want to store a string in a different format in elasticsearch then use [a ruby filter and strftime](https://discuss.elastic.co/t/converting-a-date-input-as-a-string-into-a-new-format/177498/2). If you want to change the format in which elasticsearch stores dates then you cannot do so.

---

<div class="post-metadata">

**Author:** ![Magnus\_Kessler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_kessler/32/42001_2.png) [@Magnus\_Kessler](https://discuss.elastic.co/u/Magnus_Kessler)\
**Post date:** [March 2, 2020, 2:06pm UTC](https://discuss.elastic.co/t/date-change-day-and-month-position/221606/3 "2020-03-02T14:06:40Z")

</div>

The format string in Logstash's `date` filter determines how the input data is interpreted. The filter converts the input into a format that Elasticsearch understands natively.

So, if your input looks like `12:34:56 20/02/2020` (February 20th, 2020), the format string should be `HH:mm:ss dd/MM/yyy`.

---

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [March 2, 2020, 3:22pm UTC](https://discuss.elastic.co/t/date-change-day-and-month-position/221606/4 "2020-03-02T15:22:46Z")

</div>

Thanks Magnus but i forgot to tell that the date in the logs is MM/dd/yyyy, so if I change it trows me a ["\_dateparsefailure"]

this is the format of the date in the logs

```auto
11:28:11 03/02/2020

```

---

<div class="post-metadata">

**Author:** ![Magnus\_Kessler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_kessler/32/42001_2.png) [@Magnus\_Kessler](https://discuss.elastic.co/u/Magnus_Kessler)\
**Post date:** [March 2, 2020, 3:50pm UTC](https://discuss.elastic.co/t/date-change-day-and-month-position/221606/5 "2020-03-02T15:50:03Z")

</div>

Apologies for the typo in my previous message. Please try again with this format string in the mapping: `HH:mm:ss dd/MM/yyyy`. Please not that this is the mapping used for the Elasticsearch index. With the correct mapping in place there, the string from the original log message can be interpreted correctly in Elasticsearch, and no further transformation is needed in e.g. Logstash.

I'd also add some other commonly used formats into the format string, which will help with the queries generated by Kibana. Date fields can only be queried in one of the formats defined in the format string. So, for example the full format string might look like:

`HH:mm:ss dd/MM/yyyy||strict_date_optional_time||epoch_millis`

---

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [March 3, 2020, 3:03pm UTC](https://discuss.elastic.co/t/date-change-day-and-month-position/221606/6 "2020-03-03T15:03:59Z")

</div>

Hi badger dateandtime is a field that I join, before that exists separated time and date fields, so I was thinking maybe to do this procedure only to the date field, do you think my code below is correct?

"Why don't he test this by himself" you will think.....today is 03/03/2020 😀 so I wont notice any change

```auto
    ruby {
        code => '
            t = event.get("date")
            event.set("date", Time.at(t.to_f).strftime("%d/%m/%Y"))
        '
    }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 3, 2020, 3:23pm UTC](https://discuss.elastic.co/t/date-change-day-and-month-position/221606/7 "2020-03-03T15:23:37Z")

</div>

If I remember correctly, if you event.set a field that already exists then it becomes an array, so you would want to event.remove("date") between the event.get and event.set.

---

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [March 3, 2020, 5:44pm UTC](https://discuss.elastic.co/t/date-change-day-and-month-position/221606/9 "2020-03-03T17:44:26Z")

</div>

Doesn't seems to create an array based on the rubydebug outpupt, but it send me back to the previous millennium 😁

```auto
{
          "tags" => [],
       "message" => "14:34:47 03/03/2020 name:monitor_Uptime targets:server.win state:System\\System Up Time=432472.45596 System\\System Up Time=432472.45596 type:Windows Resources unique:1952452212",
        "fields" => {
        "metrica" => "uptime"
    },
          "hora" => "14:34:47",
     "sitescope" => "claro",
      "@version" => "1",
      "segundos" => 432472.45596,
         "date" => "31/12/1969",
           "log" => {
        "offset" => 472513,
          "file" => {
            "path" => "E:\\uptime_03-03-2020_14-37-22.log"
        }
    },
          "tipo" => "Windows Resources",
    "horayfecha" => "14:34:47 31/12/1969",
            "id" => 1952452212,
         "input" => {
        "type" => "log"
    },
           "ecs" => {
        "version" => "1.4.0"
    },
       "monitor" => "monitor_Uptime",
      "hostname" => "server.win",
    "@timestamp" => 1969-12-31T17:34:47.000Z
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 3, 2020, 6:18pm UTC](https://discuss.elastic.co/t/date-change-day-and-month-position/221606/10 "2020-03-03T18:18:41Z")

</div>

What does the date field look like in the rubydebug output if you remove the ruby filter?

---

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [March 3, 2020, 6:24pm UTC](https://discuss.elastic.co/t/date-change-day-and-month-position/221606/11 "2020-03-03T18:24:43Z")

</div>

"date" =\> "03/03/2020",

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 3, 2020, 6:28pm UTC](https://discuss.elastic.co/t/date-change-day-and-month-position/221606/12 "2020-03-03T18:28:39Z")

</div>

The "Time.at(t.to\_f).strftime" assumes that t is a LogStash::Timestamp. You need to use a date filter to parse date (and overwrite it) then the ruby filter should work.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 31, 2020, 6:32pm UTC](https://discuss.elastic.co/t/date-change-day-and-month-position/221606/13 "2020-03-31T18:32:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
