# Efficicent way to use \_timestamp in visualization

**URL:** <https://discuss.elastic.co/t/efficicent-way-to-use--timestamp-in-visualization/40817>\
**Category:** Kibana\
**Created:** [February 3, 2016, 5:20am UTC](https://discuss.elastic.co/t/efficicent-way-to-use--timestamp-in-visualization/40817 "2016-02-03T05:20:13Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jamunavathy](https://avatars.discourse-cdn.com/v4/letter/j/dfb087/32.png) [@Jamunavathy](https://discuss.elastic.co/u/Jamunavathy)\
**Post date:** [February 3, 2016, 5:20am UTC](https://discuss.elastic.co/t/efficicent-way-to-use--timestamp-in-visualization/40817/1 "2016-02-03T05:20:13Z")

</div>

Hi,  
My log looks like this  
Wed Feb 12 13:42:43 2014 invalid context  
Wed Feb 12 14:00:34 2014 message not found  
Wed Feb 12 14:01:11 2014 bad address  
Fri Feb 14 15:06:50 2014 invalid context

I want to view the error message in my log, as what time error has been arised. But I don't want my log timestamp set to @timestamp. Because my log read time is not same as in the log and I don't want that as same too.

So, I filtered my log timestamp using date with the target of \_timestamp(i am using it as type date). I made a visualization with \_timestamp in x-axis and using split bar viewed the error message in kibana too. But when i tried to zoom one particular time in x-axis (say: Wed Feb 12) automatically @timestamp also moved to Feb 12 , where no logs will be there.

Is there any possible to zoom and view error details in \_timestamp (say as: view only feb 12 details).

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [February 8, 2016, 9:47pm UTC](https://discuss.elastic.co/t/efficicent-way-to-use--timestamp-in-visualization/40817/2 "2016-02-08T21:47:52Z")

</div>

When you create the index pattern, you can specify which one of your timestamp fields Kibana treats as primary. Make sure you select \_timestamp there.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:02pm UTC](https://discuss.elastic.co/t/efficicent-way-to-use--timestamp-in-visualization/40817/3 "2017-07-06T14:02:58Z")

</div>


