# Date format in Elasticsearch

**URL:** <https://discuss.elastic.co/t/date-format-in-elasticsearch/289608>\
**Category:** Logstash\
**Created:** [November 18, 2021, 2:31pm UTC](https://discuss.elastic.co/t/date-format-in-elasticsearch/289608 "2021-11-18T14:31:07Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![kibanauser4](https://avatars.discourse-cdn.com/v4/letter/k/ecd19e/32.png) [@kibanauser4](https://discuss.elastic.co/u/kibanauser4)\
**Post date:** [November 18, 2021, 2:31pm UTC](https://discuss.elastic.co/t/date-format-in-elasticsearch/289608/1 "2021-11-18T14:31:08Z")

</div>

Hello. I am trying to import a .csv file to Elasticsearch. In the .csv file there is a date field in the "yyyyMMdd" format (for example 20220326). This is what I have in my logstash conf file:

```auto
filter {
       date {
		match => ["date", "yyyyMMdd"]
		target => "date"
	}
}

```

After I imported the file I realized that it saves the date one day early, for example if I had the date 20220326 in the .csv file, this is what I get in Elasticsearch (on Kibana console): 2022-03-25T23:00:00.000Z.

How can I solve this? Thank you in advance.

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [November 18, 2021, 3:05pm UTC](https://discuss.elastic.co/t/date-format-in-elasticsearch/289608/2 "2021-11-18T15:05:59Z")

</div>

Elasticsearch will always store date with UTC timezone  
Provide timezone in your logstash filter as follow

```auto
filter {
       date {
		match => ["date", "yyyyMMdd"]
		target => "date"
        timezone => "+01:00"
	}
}

```

---

<div class="post-metadata">

**Author:** ![kibanauser4](https://avatars.discourse-cdn.com/v4/letter/k/ecd19e/32.png) [@kibanauser4](https://discuss.elastic.co/u/kibanauser4)\
**Post date:** [November 18, 2021, 4:36pm UTC](https://discuss.elastic.co/t/date-format-in-elasticsearch/289608/3 "2021-11-18T16:36:48Z")

</div>

Thank you for the reply. This didn't really solve my problem - it still saves he wrong day. Is there a way to save the date without time? For example, to be just 2022-03-26?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 18, 2021, 4:43pm UTC](https://discuss.elastic.co/t/date-format-in-elasticsearch/289608/4 "2021-11-18T16:43:27Z")

</div>

If you want the field on the document to be a [date](https://www.elastic.co/guide/en/elasticsearch/reference/current/date.html), then it is stored as milliseconds since the epoch, so it cannot store the date without the time.

If you want a string in a different format then [this](https://discuss.elastic.co/t/how-to-change-date-format-from-yyyy-mm-dd-to-dd-mmm-yyyy/132569/2) shows an example.

If you just want the date why are you using a date filter at all?

---

<div class="post-metadata">

**Author:** ![kibanauser4](https://avatars.discourse-cdn.com/v4/letter/k/ecd19e/32.png) [@kibanauser4](https://discuss.elastic.co/u/kibanauser4)\
**Post date:** [November 18, 2021, 4:50pm UTC](https://discuss.elastic.co/t/date-format-in-elasticsearch/289608/5 "2021-11-18T16:50:03Z")

</div>

The thing is, i need to import the file to an index that is already created with date fields. But if i import the file without the date filters, when i call the query i get the date as 20210362 which is good but in Kibana Discover it saves the date as "+20210326-01-01T00:00:00.000Z" and i'm not able to create any visualizations. Maybe the problem is in Kibana and i can manually change the format there?

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [November 18, 2021, 4:51pm UTC](https://discuss.elastic.co/t/date-format-in-elasticsearch/289608/6 "2021-11-18T16:51:35Z")

</div>

You can change the timezone in Kibana Advanced Settings. Default is it uses what the browser detects. Swap to UTC and see if that works for you.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/b/1b49dc57e24bf56fbe1bf4231843a9c821e71fc0.png)

---

<div class="post-metadata">

**Author:** ![kibanauser4](https://avatars.discourse-cdn.com/v4/letter/k/ecd19e/32.png) [@kibanauser4](https://discuss.elastic.co/u/kibanauser4)\
**Post date:** [November 18, 2021, 5:01pm UTC](https://discuss.elastic.co/t/date-format-in-elasticsearch/289608/7 "2021-11-18T17:01:01Z")

</div>

Sorry btw i'm very new at Elasticsearch. In my case that doesn't really change anything, cause it saves the whole date as the year aka **20210326-01-01** T00:00:00.000Z instead of **2021-03-26** T00:00:00.000Z (without using the date filters that i mentioned above)

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [November 18, 2021, 5:18pm UTC](https://discuss.elastic.co/t/date-format-in-elasticsearch/289608/8 "2021-11-18T17:18:14Z")

</div>

```auto
PUT timezone
{
  "mappings": {
    "properties": {
      "date": {
        "type": "date",
        "format": "yyyyMMdd"
      }
    }
  }
}

POST timezone/_doc
{
  "date": "20220326"
}

GET timezone/_search
#notice the date field shows exactly what you entered. No conversion.

```

Kibana in Discovery and Visualizations datetime conversion happens for each user based on the settings in Kibana.

Discover date field = `Mar 25, 2022 @ 20:00:00.000` with timezone setting to equal browser. I am -4 hours from UTC.

Discover date field = `Mar 26, 2022 @ 00:00:00.000` with timezone setting to UTC.

I think you might be missing the part where Kibana is auto translating timestamps based on your Kibana settings.

---

<div class="post-metadata">

**Author:** ![kibanauser4](https://avatars.discourse-cdn.com/v4/letter/k/ecd19e/32.png) [@kibanauser4](https://discuss.elastic.co/u/kibanauser4)\
**Post date:** [November 18, 2021, 5:30pm UTC](https://discuss.elastic.co/t/date-format-in-elasticsearch/289608/9 "2021-11-18T17:30:20Z")

</div>

I get it now. Thank you very much!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 16, 2021, 5:30pm UTC](https://discuss.elastic.co/t/date-format-in-elasticsearch/289608/10 "2021-12-16T17:30:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
