# Date/time field formatting from csv input

**URL:** <https://discuss.elastic.co/t/date-time-field-formatting-from-csv-input/326984>\
**Category:** Logstash\
**Created:** [March 4, 2023, 3:13pm UTC](https://discuss.elastic.co/t/date-time-field-formatting-from-csv-input/326984 "2023-03-04T15:13:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![karlkras](https://avatars.discourse-cdn.com/v4/letter/k/b19c9b/32.png) [@karlkras](https://discuss.elastic.co/u/karlkras)\
**Post date:** [March 4, 2023, 3:13pm UTC](https://discuss.elastic.co/t/date-time-field-formatting-from-csv-input/326984/1 "2023-03-04T15:13:48Z")

</div>

Please excuse the ignorance of my question, I'm still trying get my arms around working with elk, not my forte.  
I'm generating a csv for a report that contains a few columns that refer to date/time stamps.  
During generation I'm normalizing these fields from their original formatted state to their (assume more flexible) millisecond representation.  
Now I'm trying to work out what I need to do with these when sending to ES when processing. Do I configure a plugin to perform the conversion back to a human readable format? What is the suggested workflow to perform this?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 4, 2023, 6:49pm UTC](https://discuss.elastic.co/t/date-time-field-formatting-from-csv-input/326984/2 "2023-03-04T18:49:35Z")

</div>

> [@karlkras](#):
>
> millisecond representation

Do you mean milliseconds since the epoch? If so I would suggest using a [date](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html) filter to match the UNIX\_MS format. That will create a Timestamp object (logstash has a Timestamp data type).

When a Timestamp field is sent to elasticsearch then [date detection](https://www.elastic.co/guide/en/elasticsearch/reference/current/dynamic-field-mapping.html#date-detection) will map the field as a date (really date+time) in the index.

---

<div class="post-metadata">

**Author:** ![karlkras](https://avatars.discourse-cdn.com/v4/letter/k/b19c9b/32.png) [@karlkras](https://discuss.elastic.co/u/karlkras)\
**Post date:** [March 4, 2023, 9:19pm UTC](https://discuss.elastic.co/t/date-time-field-formatting-from-csv-input/326984/3 "2023-03-04T21:19:27Z")

</div>

Yep, that's the format I'm talking about.  
I see you answered a similar question a few years back.

> [@Convert epoch time to date](https://discuss.elastic.co/t/convert-epoch-time-to-date/223153):
>
> [Edited] I am using Logstash 7.x version I have log like below where scheduledTime is in epoch long number, {"scheduledTime":1580634058274,"processTime":1580634073293,"mailingType":1,"userId":123} I want it to be indexed to ES in below format through logstash {"scheduledTime":"Wed Mar 11 2020 14:08:11","processTime":1580634073293,"mailingType":1,"userId":123}

Sorry, I'll work on my forum searching chops.

Regards!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 1, 2023, 9:19pm UTC](https://discuss.elastic.co/t/date-time-field-formatting-from-csv-input/326984/4 "2023-04-01T21:19:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
