# Filebeat module netflow - modify netflow @timestamp by the current time

**URL:** <https://discuss.elastic.co/t/filebeat-module-netflow-modify-netflow-timestamp-by-the-current-time/217165>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 30, 2020, 11:04am UTC](https://discuss.elastic.co/t/filebeat-module-netflow-modify-netflow-timestamp-by-the-current-time/217165 "2020-01-30T11:04:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bruno1](https://avatars.discourse-cdn.com/v4/letter/b/b2d939/32.png) [@Bruno1](https://discuss.elastic.co/u/Bruno1)\
**Post date:** [January 30, 2020, 11:04am UTC](https://discuss.elastic.co/t/filebeat-module-netflow-modify-netflow-timestamp-by-the-current-time/217165/1 "2020-01-30T11:04:05Z")

</div>

Hello,

I have a problem, the netflow filebeat module keep the timestamp of inside the netflow packet. Here 1993-12-03..., but I want modify this value by the current time.

For now I have:

> Blockquote  
> {  
> "@timestamp": "1993-12-03T19:05:37.626Z",  
> "@metadata": {  
> "beat": "filebeat",  
> [...]  
> "netflow": {  
> [...]  
> "timestamp": "1993-12-03T19:05:37.626Z"  
> [...]  
> }  
> [...]  
> Blockquote

But I want this output:

> Blockquote  
> {  
> "@timestamp": "2020-01-30T12:03:00.626Z",  
> "@metadata": {  
> "beat": "filebeat",  
> [...]  
> "netflow": {  
> [...]  
> "timestamp": "1993-12-03T19:05:37.626Z"  
> [...]  
> }  
> [...]  
> Blockquote

If someone have an idea for change the value of @timestamp by the operating system time ?

Thanks

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [January 30, 2020, 5:41pm UTC](https://discuss.elastic.co/t/filebeat-module-netflow-modify-netflow-timestamp-by-the-current-time/217165/2 "2020-01-30T17:41:54Z")

</div>

So currently Filebeat reads the date on the Netflow/IPFIX header and uses that as `@timestamp` field, there's no configuration flag to use the current ingestion time instead.

However you can work around it with the script processor:

(filebeat.yml)

```auto
processors:
   - add_cloud_metadata: ~
   - add_docker_metadata: ~
   - add_kubernetes_metadata: ~
   - script:
      lang: javascript
      source: >
          function process(event) {
              event.Put('@timestamp', new Date());
          }

```

Consider adding a `when` [condition](https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html#conditions) so that it only applies to Netflow events.

* * *

About the wrong date, is the date set wrong on your netflow device or Filebeat is parsing it incorrectly? If you're unsure, can you share a pcap with the netflow traffic?

---

<div class="post-metadata">

**Author:** ![Bruno1](https://avatars.discourse-cdn.com/v4/letter/b/b2d939/32.png) [@Bruno1](https://discuss.elastic.co/u/Bruno1)\
**Post date:** [February 7, 2020, 2:50pm UTC](https://discuss.elastic.co/t/filebeat-module-netflow-modify-netflow-timestamp-by-the-current-time/217165/3 "2020-02-07T14:50:24Z")

</div>

Thanks a lot 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2020, 2:50pm UTC](https://discuss.elastic.co/t/filebeat-module-netflow-modify-netflow-timestamp-by-the-current-time/217165/4 "2020-03-06T14:50:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
