# Elasticsearch output: LogStash::Error: timestamp field is missing

**URL:** <https://discuss.elastic.co/t/elasticsearch-output-logstash-timestamp-field-is-missing/197888>\
**Category:** Logstash\
**Created:** [September 3, 2019, 2:58pm UTC](https://discuss.elastic.co/t/elasticsearch-output-logstash-timestamp-field-is-missing/197888 "2019-09-03T14:58:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ouss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ouss/32/53523_2.png) [@ouss](https://discuss.elastic.co/u/ouss)\
**Post date:** [September 3, 2019, 2:58pm UTC](https://discuss.elastic.co/t/elasticsearch-output-logstash-timestamp-field-is-missing/197888/1 "2019-09-03T14:58:23Z")

</div>

Hello,

I have an elasticsearch output working without any problem

```
elasticsearch {
  hosts => ["${LOGS_ELASTICSEARCH_CLUSTER}:443"]
  ssl => true
  index => "cwl-%{+YYYY.MM.dd}"
  document_type => "log"
}

```

I wanted to redirect some type of logs to a new elasticsearch index but I'm getting this error

```
[2019-09-03T14:39:00,242][FATAL][logstash.runner] An unexpected error occurred! {:error=>#<LogStash::Error: timestamp field is missing>, :backtrace=>["org/logstash/ext/JrubyEventExtLibrary.java:202:in `sprintf'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-7.3.8-java/lib/logstash/outputs/elasticsearch/common.rb:172:in `event_action_params'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-7.3.8-java/lib/logstash/outputs/elasticsearch/common.rb:48:in `event_action_tuple'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-7.3.8-java/lib/logstash/outputs/elasticsearch/common.rb:42:in `multi_receive'", "org/jruby/RubyArray.java:2414:in `map'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-7.3.8-java/lib/logstash/outputs/elasticsearch/common.rb:42:in `multi_receive'", "/usr/share/logstash/logstash-core/lib/logstash/output_delegator_strategies/shared.rb:13:in `multi_receive'", "/usr/share/logstash/logstash-core/lib/logstash/output_delegator.rb:47:in `multi_receive'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:420:in `output_batch'", "org/jruby/RubyHash.java:1342:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:419:in `output_batch'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:365:in `worker_loop'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:330:in `start_workers'"]}

No newer events found at the moment. Retry.

```

**The new output is:**

```
  if "http" in [tags] {
    elasticsearch {
      hosts => ["${LOGS_ELASTICSEARCH_CLUSTER}:443"]
      ssl => true
      index => "cwl-http-%{+YYYY.MM.dd}"
      document_type => "log"
    }
  }
  else {
    elasticsearch {
      hosts => ["${LOGS_ELASTICSEARCH_CLUSTER}:443"]
      ssl => true
      index => "cwl-%{+YYYY.MM.dd}"
      document_type => "log"
    }
  }

```

I modified my filter like this

```
 ### HTTP logs
 if [logger_name] == "HttpLoggerService" {
   mutate {
     add_tag => ["http"]
   }
 }

```

any thing wrong in my configuration ?

Thanks!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 3, 2019, 4:15pm UTC](https://discuss.elastic.co/t/elasticsearch-output-logstash-timestamp-field-is-missing/197888/2 "2019-09-03T16:15:24Z")

</div>

> [@ouss](#):
>
> An unexpected error occurred! {:error=\>#\<LogStash::Error: timestamp field is missing\>

You are using %{+YYYY.MM.dd} in your index name, but the event does not have a @timestamp field from which to extract the year, month and day.

If the only difference between the two elasticsearch outputs is the index name it would be slightly more efficient to put the index name into a [@metadata] field and use a sprintf reference to it.

---

<div class="post-metadata">

**Author:** ![ouss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ouss/32/53523_2.png) [@ouss](https://discuss.elastic.co/u/ouss)\
**Post date:** [September 4, 2019, 10:00am UTC](https://discuss.elastic.co/t/elasticsearch-output-logstash-timestamp-field-is-missing/197888/3 "2019-09-04T10:00:02Z")

</div>

It solved my problem, Thanks @Badger 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 2, 2019, 10:00am UTC](https://discuss.elastic.co/t/elasticsearch-output-logstash-timestamp-field-is-missing/197888/4 "2019-10-02T10:00:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
