# Date filter in logstash

**URL:** <https://discuss.elastic.co/t/date-filter-in-logstash/294431>\
**Category:** Logstash\
**Created:** [January 14, 2022, 4:03pm UTC](https://discuss.elastic.co/t/date-filter-in-logstash/294431 "2022-01-14T16:03:34Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![MKH](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mkh/32/100766_2.png) [@MKH](https://discuss.elastic.co/u/MKH)\
**Post date:** [January 14, 2022, 4:03pm UTC](https://discuss.elastic.co/t/date-filter-in-logstash/294431/1 "2022-01-14T16:03:34Z")

</div>

Hi,

I am trying to use Date filter of the logstash to create a timestamp on my data stored in Elasticsearch. The timestamp in my data is in Linux format and I want to change it to some standard format like as "dd MMM yyyy HH:mm:ss". I have two questions to ask:  
1- I wonder if it is possible to change the UNIX time format to the format I want within the dat filter or I should first change the format and then parse the new format into the filter?

2- I have used the filter as below but I cannot see any timestamp in my data stored in the index of Elasticsearch! (start\_time is the field in my data containing the Unix time)

```auto
...
filter {
    date {
        match => ["start_time", 'UNIX']
        target => "start_time"
    }
...

```

Could anybody please help out?

Thanks

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 14, 2022, 4:51pm UTC](https://discuss.elastic.co/t/date-filter-in-logstash/294431/2 "2022-01-14T16:51:52Z")

</div>

Can you share an example of how the value of the `start_time` field looks like?

Maybe you have epoch time with miliseconds, then you would need to use `UNIX_MS`.

---

<div class="post-metadata">

**Author:** ![MKH](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mkh/32/100766_2.png) [@MKH](https://discuss.elastic.co/u/MKH)\
**Post date:** [January 14, 2022, 5:04pm UTC](https://discuss.elastic.co/t/date-filter-in-logstash/294431/3 "2022-01-14T17:04:31Z")

</div>

Thank you @leandrojmp for the response. This is an example of my time:  
"start\_time": 1618484099000, I know it is in miliseconds and I can convert it to the format I want with this command in linux (date -d @time). Should I use UNIX\_MS?

Thanks.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 14, 2022, 5:28pm UTC](https://discuss.elastic.co/t/date-filter-in-logstash/294431/4 "2022-01-14T17:28:23Z")

</div>

Yes, just change from `UNIX` to `UNIX_MS` in your date filter, it should work.

---

<div class="post-metadata">

**Author:** ![MKH](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mkh/32/100766_2.png) [@MKH](https://discuss.elastic.co/u/MKH)\
**Post date:** [January 14, 2022, 7:20pm UTC](https://discuss.elastic.co/t/date-filter-in-logstash/294431/5 "2022-01-14T19:20:13Z")

</div>

> [@leandrojmp](#):
>
> UNIX\_MS

@leandrojmp Thank you so much for your quick and very helpful response. It is working by UNIX\_MS. The only problem I have is that when I send a bulk of 3 docs to my index it seems only the last one is stored in the index. I have tried to read my index content both with a curl command in my terminal and also by creating the index in kibana to visualize it. Both results are the same!  
I also save this data in a file (as logstash output filter) and I can see all 3 docs in the output file. Could you please help about this too? Any thing I may have missed?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 14, 2022, 10:39pm UTC](https://discuss.elastic.co/t/date-filter-in-logstash/294431/6 "2022-01-14T22:39:09Z")

</div>

Since this is a different issue, I would suggest that you open another topic, describe the issue and share your logstash pipeline.

---

<div class="post-metadata">

**Author:** ![MKH](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mkh/32/100766_2.png) [@MKH](https://discuss.elastic.co/u/MKH)\
**Post date:** [January 16, 2022, 7:16pm UTC](https://discuss.elastic.co/t/date-filter-in-logstash/294431/7 "2022-01-16T19:16:06Z")

</div>

Ok. Thank you so much.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 13, 2022, 7:16pm UTC](https://discuss.elastic.co/t/date-filter-in-logstash/294431/8 "2022-02-13T19:16:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
