# ES timestamp index not working while creating index

**URL:** <https://discuss.elastic.co/t/es-timestamp-index-not-working-while-creating-index/134104>\
**Category:** Elasticsearch\
**Created:** [May 31, 2018, 7:47pm UTC](https://discuss.elastic.co/t/es-timestamp-index-not-working-while-creating-index/134104 "2018-05-31T19:47:29Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![chakriv](https://avatars.discourse-cdn.com/v4/letter/c/c2a13f/32.png) [@chakriv](https://discuss.elastic.co/u/chakriv)\
**Post date:** [May 31, 2018, 7:47pm UTC](https://discuss.elastic.co/t/es-timestamp-index-not-working-while-creating-index/134104/1 "2018-05-31T19:47:29Z")

</div>

Elastic search index template

// {  
"order": 0,  
"template": "jobbot",  
"settings": {},  
"mappings": {  
"doc": {  
"properties": {  
"request": {  
"type": "keyword"  
},  
"timestamp": {  
"type": "date" ,  
"format": "yyyy-MM-dd HH:mm:ss||yyyy-MM-dd||epoch\_millis"  
}

```
            }
        }
    },
 "aliases": {}

```

} //

sample entry (record in ES/kibana):

//{  
"\_index": "jobbot",  
"\_type": "doc",  
"\_id": "2018-05-16 14:02:02.601520774 +0000 UTC m=+61284.555636238",  
"\_version": 1,  
"\_score": 1,  
"\_source": {  
"timestamp": "2018-05-16 14:02:02.601520774 +0000 UTC m=+61284.555636238",  
"request": "individualreq"  
}  
}//

 ![47](https://us1.discourse-cdn.com/elastic/original/3X/7/3/73e2b3882fc05202712342cbf1281d5f241c7580.jpg)

how do i create timestamp field for each entry and have search results by timestamp configured?

thanks  
Chakri

---

<div class="post-metadata">

**Author:** ![jscubida](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jscubida/32/24214_2.png) [@jscubida](https://discuss.elastic.co/u/jscubida)\
**Post date:** [June 1, 2018, 2:53pm UTC](https://discuss.elastic.co/t/es-timestamp-index-not-working-while-creating-index/134104/2 "2018-06-01T14:53:54Z")

</div>

It looks like you have a mapping that isn't able to handle the timestamp in your sample entry, which includes fractions of a second and additional information after the timezone. It might be easier to format your timestamp data as one of the built-in formats. Otherwise, you'll need to revise the mapping you have. See [this](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-date-format.html#custom-date-formats) for more formatting info. Once you have the correct format, Kibana should recognize that timestamp is a valid time field.

---

<div class="post-metadata">

**Author:** ![chakriv](https://avatars.discourse-cdn.com/v4/letter/c/c2a13f/32.png) [@chakriv](https://discuss.elastic.co/u/chakriv)\
**Post date:** [June 1, 2018, 3:34pm UTC](https://discuss.elastic.co/t/es-timestamp-index-not-working-while-creating-index/134104/3 "2018-06-01T15:34:30Z")

</div>

thanks much.. yeah i figured date format is causing this..however when i try to re-index with adding metadata field for timestamp using logstash filters..its taking current time as timestamp not the timestamp field in message..any way to extract that out?

filter {

mutate {  
add\_field =\> { "[@metadata][source][timestamp]" =\> "[@metadata][timestamp]" }  
}

}

after conversion data json:

{  
"\_index": "jobbot-2018.06.01",  
"\_type": "doc",  
"\_id": "Uvnwu2MBclkPHF46kSv5",  
"\_version": 1,  
"\_score": 2,  
"\_source": {  
"@version": "1",  
"timestamp": "2018-05-21 17:47:50.605260774 +0000 UTC m=+330187.478365347",  
"@timestamp": "2018-06-01T15:21:32.046Z",  
"request": "Usage"  
},  
"fields": {  
"@timestamp": [  
"2018-06-01T15:21:32.046Z"  
]  
}  
}

before conversion json data:

{  
"\_index": "sejobbot",  
"\_type": "doc",  
"\_id": "2018-05-16 14:02:02.601520774 +0000 UTC m=+61284.555636238",  
"\_version": 1,  
"\_score": 1,  
"\_source": {  
"timestamp": "2018-05-16 14:02:02.601520774 +0000 UTC m=+61284.555636238",  
"request": "individualContributor"  
}  
}

---

<div class="post-metadata">

**Author:** ![jscubida](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jscubida/32/24214_2.png) [@jscubida](https://discuss.elastic.co/u/jscubida)\
**Post date:** [June 1, 2018, 8:35pm UTC](https://discuss.elastic.co/t/es-timestamp-index-not-working-while-creating-index/134104/4 "2018-06-01T20:35:59Z")

</div>

I believe Logstash is inserting the current time based on [this answer](https://discuss.elastic.co/t/add-field-timestamp-with-current-time/59862). Since your timestamp field is a string upon being input into Logstash, I think you'll have to format the string and convert it into a date. [This](https://discuss.elastic.co/t/conver-string-to-date-or-replace-timestamp-solved/32957) should be of assistance.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 29, 2018, 8:36pm UTC](https://discuss.elastic.co/t/es-timestamp-index-not-working-while-creating-index/134104/5 "2018-06-29T20:36:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
