# Day of the week with non UTC timestamps

**URL:** <https://discuss.elastic.co/t/day-of-the-week-with-non-utc-timestamps/291066>\
**Category:** Logstash\
**Created:** [December 6, 2021, 3:30pm UTC](https://discuss.elastic.co/t/day-of-the-week-with-non-utc-timestamps/291066 "2021-12-06T15:30:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Malec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/malec/32/46127_2.png) [@Malec](https://discuss.elastic.co/u/Malec)\
**Post date:** [December 6, 2021, 3:30pm UTC](https://discuss.elastic.co/t/day-of-the-week-with-non-utc-timestamps/291066/1 "2021-12-06T15:30:42Z")

</div>

Hi everyone,  
I have logs in a `dd/MM/YYYY HH:mm:ss` format using the CET timezone, and I am trying to extract the Day of the week for **CET and not UTC**.  
We used this at first

```auto
date {
  match => ["date", "dd/MM/YYYY HH:mm:ss"]
  timezone => "Europe/Paris"
}
mutate {
  add_field => {"dow" => "%{+EEEE}"}
}

```

But realized that any logs that happened between 00:00AM and 00:59 AM would get the "dow" field set to the previous day (which is logical since it's still the same day in UTC time). For some reason I don't understand, Logstash corrects the time and sends it in UTC when it could be sending it with the timezone delta (`Z+0100`).

We found an ugly way to trick logstash by making it believe all logs were in UTC before injecting "dow" and then correcting the timestamps.

```auto
date {
  match => ["date", "dd/MM/YYYY HH:mm:ss"]
  timezone => "UTC"
  add_field => {"dow" => "%{+EEEE}"}
}

date {
  match => ["date", "dd/MM/YYYY HH:mm:ss"]
  target => "@timestamp"
  timezone => "Europe/Paris"
 } 

```

This is certainly not the best way to do this and I was wondering if the community could help me figure out a cleaner way?

Bonus points if there's a way to change the day of week from english to any other language without having to resort to a translate filter 😄. The `locale` option seems to be usable only for parsing, and not for outputting `%{+EEEE}`

Any help is much appreciated.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 6, 2021, 5:51pm UTC](https://discuss.elastic.co/t/day-of-the-week-with-non-utc-timestamps/291066/2 "2021-12-06T17:51:46Z")

</div>

> [@Malec](#):
>
> This is certainly not the best way to do this

Actually I think it is. sprintf references [use](https://discuss.elastic.co/t/extract-day-month-and-year-from-a-date-field-changing-timezone/267646/2) @timestamp, which is expected to be in UTC. There is an [issue](https://github.com/elastic/logstash/issues/2315) about being able to specify locale/timezone for a sprintf reference, but it has been inactive for years.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 3, 2022, 5:52pm UTC](https://discuss.elastic.co/t/day-of-the-week-with-non-utc-timestamps/291066/3 "2022-01-03T17:52:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
