# \[Elastic Cloud\] Configure Filebeat to use timestamp from LogFile

**URL:** <https://discuss.elastic.co/t/elastic-cloud-configure-filebeat-to-use-timestamp-from-logfile/229711>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 24, 2020, 7:40pm UTC](https://discuss.elastic.co/t/elastic-cloud-configure-filebeat-to-use-timestamp-from-logfile/229711 "2020-04-24T19:40:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Regis\_Oliveira](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/regis_oliveira/32/67082_2.png) [@Regis\_Oliveira](https://discuss.elastic.co/u/Regis_Oliveira)\
**Post date:** [April 24, 2020, 7:40pm UTC](https://discuss.elastic.co/t/elastic-cloud-configure-filebeat-to-use-timestamp-from-logfile/229711/1 "2020-04-24T19:40:21Z")

</div>

Hello!

I'm evaluating Elastic Cloud and couldn't realize how to configure Filebeat to use the timestamp provided in my log file instead of use the time when the file is being read.

Actually, when searching on Kibana, the documents are show as this:  
`Apr 24, 2020 @ 16:30:48.998	2020-04-24 18:48:10.455 INFO ServersManager:544 - [0176-0178-730105] Réplica tabela SYNC_STATUS: concluido. 0 recs em 0 secs`

And I'd like to use as this:  
`Apr 24, 2020 @ 18:48:10.455	INFO ServersManager:544 - [0176-0178-730105] Réplica tabela SYNC_STATUS: concluido. 0 recs em 0 secs`

 ![Captura de Tela 2020-04-24 às 16.33.01](https://us1.discourse-cdn.com/elastic/original/3X/5/5/55301a3d03da549b745c32aac2dddae3bd17817e.png)

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 24, 2020, 8:39pm UTC](https://discuss.elastic.co/t/elastic-cloud-configure-filebeat-to-use-timestamp-from-logfile/229711/2 "2020-04-24T20:39:18Z")

</div>

Hi @Regis_Oliveira, welcome to the Elastic community forums!

To achieve what you want you'll need to take two steps in your Filebeat configuration:

1. You'll want to parse out the timestamp portion from your log messages. For this take a look at the [`dissect` processor](https://www.elastic.co/guide/en/beats/filebeat/master/dissect.html). If you haven't used Filebeat processors before, you'll want to read their [documentation](https://www.elastic.co/guide/en/beats/filebeat/master/filtering-and-enhancing-data.html).

2. Once you've parsed your timestamp into it's own field, you'll want to use it to set the `@timestamp` field that Kibana typically looks at for timeseries data. For this take a look at the [`timestamp` processor](https://www.elastic.co/guide/en/beats/filebeat/master/processor-timestamp.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 22, 2020, 8:47pm UTC](https://discuss.elastic.co/t/elastic-cloud-configure-filebeat-to-use-timestamp-from-logfile/229711/3 "2020-05-22T20:47:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
