# Date Variable on index name

**URL:** <https://discuss.elastic.co/t/date-variable-on-index-name/353321>\
**Category:** Logstash\
**Created:** [February 15, 2024, 3:42am UTC](https://discuss.elastic.co/t/date-variable-on-index-name/353321 "2024-02-15T03:42:18Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [February 15, 2024, 3:42am UTC](https://discuss.elastic.co/t/date-variable-on-index-name/353321/1 "2024-02-15T03:42:18Z")

</div>

Hello there,

I'm curious when there's a pipeline with configured output like this:

```auto
index => "log-%{+YYYY.MM.dd}"

```

where is the date variable referring to?

- the timestamp on the log, or
- the timestamp of the logstash server?

if it refers to the timestamp of the logstash server, then why is there an index with no date on its name in my cluster? I've already checked the NTP on my logstash servers and everything's fine. the log inside the index may not have a timestamp but if the date in the index name refers to the server time, then it should be no problem right? The index name should still have the date on it but things are different here. what could be the problem?

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 15, 2024, 3:51am UTC](https://discuss.elastic.co/t/date-variable-on-index-name/353321/2 "2024-02-15T03:51:14Z")

</div>

It is [filled in](https://github.com/elastic/logstash/blob/3c9db658bc7c64eb0da2ed40936382535a84ff21/logstash-core/src/main/java/org/logstash/StringInterpolation.java#L82) using the [@timestamp] field of the event.

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [February 15, 2024, 3:54am UTC](https://discuss.elastic.co/t/date-variable-on-index-name/353321/3 "2024-02-15T03:54:37Z")

</div>

oh, it makes the situation clear then. Thanks

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [February 15, 2024, 4:35am UTC](https://discuss.elastic.co/t/date-variable-on-index-name/353321/4 "2024-02-15T04:35:23Z")

</div>

As Badger said it's using @timestamp which can be sent by beats or app, if is not, LS will use UTC time from LS server.

If you have a date conversion by the date plugin, default is `target=> "@timestamp"` which overwrites LS local time with your matching field - in the most cases is the log time.  
If you delete the @timestamp field, in some cases, the output will not have idea about time which means log-%{+YYYY.MM.dd} will create the index: _log-_ , without the date in naming.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 14, 2024, 4:36am UTC](https://discuss.elastic.co/t/date-variable-on-index-name/353321/5 "2024-03-14T04:36:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
