# Date conversion with Logstash

**URL:** <https://discuss.elastic.co/t/date-conversion-with-logstash/302947>\
**Category:** Logstash\
**Created:** [April 21, 2022, 4:09pm UTC](https://discuss.elastic.co/t/date-conversion-with-logstash/302947 "2022-04-21T16:09:43Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lynow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lynow/32/98866_2.png) [@Lynow](https://discuss.elastic.co/u/Lynow)\
**Post date:** [April 21, 2022, 4:09pm UTC](https://discuss.elastic.co/t/date-conversion-with-logstash/302947/1 "2022-04-21T16:09:43Z")

</div>

Hello, I currently have a problem for date conversion with Logstash.

I receive logs including dates in epoche format (UNIX), so I added the following filters to modify them. Namely, I have multiple date fields, as you can see.

My configuration :

```auto
filter {
  json {
    source => "message"
  }
  date {
     match => ["startDate","UNIX_MS"]
     target => "startDate"
     timezone => "UTC"
  }
  date {
     match => ["endDate","UNIX_MS"]
     target => "endDate"
     timezone => "UTC"
  }
  date {
     match => ["updatedAt","UNIX_MS"]
     target => "updatedAt"
     timezone => "UTC"
  }
  date {
     match => ["createdAt","UNIX_MS"]
     target => "createdAt"
     timezone => "UTC"
  }
}

```

In this case, I get, in Elasticsearch, the dates: 2,022 for every fields of date.

On the other hand, if I remove the target in one of the dates, this modifies the @timestamp with the correct date, but each date must keep its field name...

Any ideas ?

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [April 21, 2022, 4:32pm UTC](https://discuss.elastic.co/t/date-conversion-with-logstash/302947/2 "2022-04-21T16:32:22Z")

</div>

Most likely your date [format](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-date-format.html) coming in isn't `UNIX_MS`. Can you post a sample of your data?

---

<div class="post-metadata">

**Author:** ![Lynow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lynow/32/98866_2.png) [@Lynow](https://discuss.elastic.co/u/Lynow)\
**Post date:** [April 22, 2022, 7:15am UTC](https://discuss.elastic.co/t/date-conversion-with-logstash/302947/3 "2022-04-22T07:15:38Z")

</div>

Yes of course. An example of date in json lines :

```auto
"startDate":1649751840000

```

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [April 22, 2022, 11:07am UTC](https://discuss.elastic.co/t/date-conversion-with-logstash/302947/4 "2022-04-22T11:07:35Z")

</div>

Looks like your pipeline works so the next step would be to look at the mapping for those fields.

**Conf**

```auto
input {
  generator {
      lines => ['{"startDate":1649751840000}']
      codec => json
      count => 1
  }
}
filter {
  date {
    match => ["startDate","UNIX_MS"]
    target => "startDate"
    timezone => "UTC"
  }  
}
output {
  stdout { codec => json_lines }
}

```

**Output**

```auto
"startDate": "2022-04-12T08:24:00.000Z"

```

---

<div class="post-metadata">

**Author:** ![Lynow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lynow/32/98866_2.png) [@Lynow](https://discuss.elastic.co/u/Lynow)\
**Post date:** [April 22, 2022, 2:04pm UTC](https://discuss.elastic.co/t/date-conversion-with-logstash/302947/5 "2022-04-22T14:04:33Z")

</div>

Ok well finally, I chose to take into account only the "startDate" field and convert it with the "@timestamp" target. I don't need the other dates.

However, yes it is indeed strange...

Thanks !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 20, 2022, 2:04pm UTC](https://discuss.elastic.co/t/date-conversion-with-logstash/302947/6 "2022-05-20T14:04:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
