# Date time with time multifield

**URL:** <https://discuss.elastic.co/t/date-time-with-time-multifield/349513>\
**Category:** Elasticsearch\
**Created:** [December 17, 2023, 2:03pm UTC](https://discuss.elastic.co/t/date-time-with-time-multifield/349513 "2023-12-17T14:03:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![RRGTHWAR1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rrgthwar1/32/130084_2.png) [@RRGTHWAR1](https://discuss.elastic.co/u/RRGTHWAR1)\
**Post date:** [December 17, 2023, 2:03pm UTC](https://discuss.elastic.co/t/date-time-with-time-multifield/349513/1 "2023-12-17T14:03:16Z")

</div>

This has come up from time to time, but I haven’t seen any definitive answers. Is it possible to have a time-only multi-field in a date time field? For example, created\_date would be the full datetime, and created\_date.time would store only the time portion, indexed for filtering/sorting/querying.

From what I’ve gathered, this might not be possible because datetimes are internally stored as milliseconds after epoch. Would there be some way to store the modulo of the milliseconds at indexing time to remove the days from them, and then use that value for range filtering?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 18, 2023, 1:18am UTC](https://discuss.elastic.co/t/date-time-with-time-multifield/349513/2 "2023-12-18T01:18:58Z")

</div>

Hi @RRGTHWAR1 Welcome to the community...

> [@RRGTHWAR1](#):
>
> For example, created\_date would be the full datetime, and created\_date.time would store only the time portion,

No that is not supported / that is not how multifields work... See [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/multi-fields.html#multi-fields)

> It is often useful to index the same field in different ways for different purposes. This is the purpose of _multi-fields_ . For instance, a `string` field could be mapped as a `text` field for full-text search, and as a `keyword` field for sorting or aggregations:

you will need to use 2 separate fields like

```auto
created_date 
created_time_of_day

```

> [@RRGTHWAR1](#):
>
> Would there be some way to store the modulo of the milliseconds at indexing time to remove the days from them

Yes you would do this at index time using. an ingest pipeline with a script processor... but the result would be a long

I think I showed just how to do something similar recently as a runtime field a script processor would be very similar

> [@Extracting time from @timestamp field using Runtime](https://discuss.elastic.co/t/extracting-time-from-timestamp-field-using-runtime/348468/11):
>
> Add the mapping to the template and a script process to the ingest pipeline... and you do not need the @ for every timestamp / date that is just and nameing convtion for the special field @timestamp take a look at this... POST \_ingest/pipeline/\_simulate { "pipeline": { "processors": [{ "script": { "lang": "painless", "source": """ZonedDateTime zdt = ZonedDateTime.parse(ctx['@timestamp'], DateTimeFormatter.ISO\_ZONED\_DATE\_TIME); String time\_of\_…

This would actually create a "keyword" that shows the time of day it could be filtered...

If you just want ms, that would be a `long`, and of course, that would not be a `date`. It would just be a `long`...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2024, 1:19am UTC](https://discuss.elastic.co/t/date-time-with-time-multifield/349513/3 "2024-01-15T01:19:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
