# Dynamic Timezone in Logstash csv

**URL:** <https://discuss.elastic.co/t/dynamic-timezone-in-logstash-csv/247502>\
**Category:** Logstash\
**Created:** [September 4, 2020, 8:33am UTC](https://discuss.elastic.co/t/dynamic-timezone-in-logstash-csv/247502 "2020-09-04T08:33:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rakku](https://avatars.discourse-cdn.com/v4/letter/r/958977/32.png) [@Rakku](https://discuss.elastic.co/u/Rakku)\
**Post date:** [September 4, 2020, 8:33am UTC](https://discuss.elastic.co/t/dynamic-timezone-in-logstash-csv/247502/1 "2020-09-04T08:33:03Z")

</div>

Hi there, Im completely new to pretty much anything here and got introduced at my workplace to ELK with the words: "We use ELK here, we have this and this problem, fix it".  
So here I am, with little to none knowledge on the matter.

Premise:

We get log/files from all over the world, meaning that the timezone varies all over the place.  
They´ll get put into Logstash with the following csv.

```auto
   input {
      file {
        path => "/data/mauser/*.log"
        start_position => "beginning"
        sincedb_path => "/dev/null"
      }
    }

    filter {
      csv {
        separator => "|"
        columns => ["timestamp", "version", "mainProcessID", "mainThreadID", "currentThreadID", "programmID", "severity", "module", "sessionID", "message"]
          }
            
       date {
            match => ["timestamp", "yyyy-MM-dd'T'HH:mm:ss'.'SSS'+02'"]
            }    
    }

    output {
      elasticsearch {
        hosts => ["imagine IP here"]
        index => "test_logs33"
      }
    } 

```

Example log:

`2020-09-02T16:40:20.681+02|1.0.0|00011392|00000001|00000001|p201820903srv|I|Log|b6f584e247f740ad93da672008d80c8c|"Logger started with loglevel Verbose"`

The important part here is, that the timezone is hardcoded in the filter with extempting the +02 for it to be recognized as something not to be parsed.  
Is there a syntax for a placeholder character so I can just always extempt the last 3 characters from parsing dynamicly?

The +02 in the logs would change depending on the timezone they come from, therefore my current "solution" with hardcoding +02 only works for one static timezone.

If you have any other solution, Im all totally open for it.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 4, 2020, 1:20pm UTC](https://discuss.elastic.co/t/dynamic-timezone-in-logstash-csv/247502/2 "2020-09-04T13:20:46Z")

</div>

```
mutate { gsub => ["timestamp", ".{3}$", ""] }

```

will delete the last three characters of the [timestamp] field.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 2, 2020, 1:20pm UTC](https://discuss.elastic.co/t/dynamic-timezone-in-logstash-csv/247502/3 "2020-10-02T13:20:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
