# Filebeat uses process time instead event time

**URL:** <https://discuss.elastic.co/t/filebeat-uses-process-time-instead-event-time/273646>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 21, 2021, 9:52am UTC](https://discuss.elastic.co/t/filebeat-uses-process-time-instead-event-time/273646 "2021-05-21T09:52:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nflinenberg](https://avatars.discourse-cdn.com/v4/letter/n/3be4f8/32.png) [@nflinenberg](https://discuss.elastic.co/u/nflinenberg)\
**Post date:** [May 21, 2021, 9:52am UTC](https://discuss.elastic.co/t/filebeat-uses-process-time-instead-event-time/273646/1 "2021-05-21T09:52:49Z")

</div>

Hi all,

Hope you can help me out for the following.

We've setup and Elasticstack and configured filebeat to send json logs to elasticsearch, using this configuration:

```auto
    filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /log/job-json/job-json-*.log
  json.keys_under_root: true
  json.overwrite_keys: true
  json.expand_keys: false
  fields:
    - document_type: application_job_log
  fields_under_root: true
  keep_null: true
  publisher_pipeline.disable_host: true
  index: "app-job-%{+yyyy.MM.dd}"
  document_id: "logger"
- type: log
  enabled: true
  paths:
    - /log/error-json/error-json-*.log
  json.keys_under_root: true
  json.overwrite_keys: true
  json.expand_keys: false
  fields:
    document_type: application_error_log
  fields_under_root: true
  keep_null: true
  publisher_pipeline.disable_host: true
  index: "app-err-%{+yyyy.MM.dd}"
  document_id: "logger"

filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: false

output.elasticsearch:
  enabled: true
  hosts: ["https://0.0.0.0:9200"]
  ssl.certificate_authorities: ["/some/pem/file.pem"]
  username: "ispy"
  password: "verysecret"
  indices:
    - index: "app-job-%{+yyyy.MM.dd}"
      when.contains:
        document_type: "application_job_log"
    - index: "app-err-%{+yyyy.MM.dd}"
      when.contains:
        document_type: "application_error_log"

```

above code outputs something like this:

```auto
    {
  "@timestamp": "2021-05-21T08:49:02.835Z",
  "@metadata": {
    "beat": "filebeat",
    "type": "_doc",
    "version": "7.12.1",
    "raw_index": "app-job-2021.05.21"
  },
  "timestamp": "1621586880034",
  "level": "INFO",
  "logger": "com.ourcompany.beehive.core.internal.job.JobExecutor"
}

```

as you can see, there two timestamp fields:  
@timestamp  
and  
timestamp

@timestamp = the time when filebeat reads the event  
timestamp = the epoch time of the logged event

we want to use the logged event timestamp to be used as the @timestamp. this so that we have the events in a historical correct order.

However, we are unable to get it working.

Hope you guys and girls can help out in this matter.

Kr,  
Nathan

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 21, 2021, 12:15pm UTC](https://discuss.elastic.co/t/filebeat-uses-process-time-instead-event-time/273646/2 "2021-05-21T12:15:38Z")

</div>

You can use the filebeat timestamp processor, [Timestamp | Filebeat Reference [7.12] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/processor-timestamp.html) or the elasticsearch date ingest processor, [Date processor | Elasticsearch Guide [7.12] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/date-processor.html) to parse the `timestamp` field into the `@timestamp` field.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 18, 2021, 2:15pm UTC](https://discuss.elastic.co/t/filebeat-uses-process-time-instead-event-time/273646/3 "2021-06-18T14:15:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
