# Format for timestamps

**URL:** <https://discuss.elastic.co/t/format-for-timestamps/252878>\
**Category:** Kibana\
**Created:** [October 21, 2020, 5:12pm UTC](https://discuss.elastic.co/t/format-for-timestamps/252878 "2020-10-21T17:12:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![georgemichael](https://avatars.discourse-cdn.com/v4/letter/g/ea666f/32.png) [@georgemichael](https://discuss.elastic.co/u/georgemichael)\
**Post date:** [October 21, 2020, 5:12pm UTC](https://discuss.elastic.co/t/format-for-timestamps/252878/1 "2020-10-21T17:12:27Z")

</div>

I am working on some logging software and was wondering what format kibana indexes timestamps. I was thinking of using something similar to log.go for formatting log header to buffer as seen here:

```auto
func (l *Logger) formatHeader(buf *[]byte, t time.Time, file string, line int) {
	if l.flag&Lmsgprefix == 0 {
		*buf = append(*buf, l.prefix...)
	}
	if l.flag&(Ldate|Ltime|Lmicroseconds) != 0 {
		if l.flag&LUTC != 0 {
			t = t.UTC()
		}
		if l.flag&Ldate != 0 {
			year, month, day := t.Date()
			itoa(buf, year, 4)
			*buf = append(*buf, '/')
			itoa(buf, int(month), 2)
			*buf = append(*buf, '/')
			itoa(buf, day, 2)
			*buf = append(*buf, ' ')
		}
		if l.flag&(Ltime|Lmicroseconds) != 0 {
			hour, min, sec := t.Clock()
			itoa(buf, hour, 2)
			*buf = append(*buf, ':')
			itoa(buf, min, 2)
			*buf = append(*buf, ':')
			itoa(buf, sec, 2)
			if l.flag&Lmicroseconds != 0 {
				*buf = append(*buf, '.')
				itoa(buf, t.Nanosecond()/1e3, 6)
			}
			*buf = append(*buf, ' ')
		}
	}

```

Any info would be appreciated!

---

<div class="post-metadata">

**Author:** ![lukeelmers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukeelmers/32/35230_2.png) [@lukeelmers](https://discuss.elastic.co/u/lukeelmers)\
**Post date:** [October 21, 2020, 8:46pm UTC](https://discuss.elastic.co/t/format-for-timestamps/252878/2 "2020-10-21T20:46:23Z")

</div>

There are two separate concepts to be aware of here: The first is how Kibana _displays_ dates, and the second is how Elasticsearch _indexes_ them.

Kibana currently uses [Moment JS](https://momentjs.com/) for parsing dates that are displayed. Moment [recognizes ISO 8601 and RFC 2822 date formats](https://momentjs.com/docs/#/parsing/string/), with a fallback to the native JavaScript `Date`.

Elasticsearch [date fields](https://www.elastic.co/guide/en/elasticsearch/reference/current/date.html) are internally converted to UTC and stored as a long representing milliseconds-since-epoch, but can be retrieved with a number of [built-in formats](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-date-format.html#built-in-date-formats). For example, the Discover app in Kibana will try to request any date fields in `date_time` format to get back the ISO 8601 date string, which Moment JS then converts to whatever `dateFormat` is specified [in Kibana's advanced settings](https://www.elastic.co/guide/en/kibana/current/advanced-options.html#kibana-general-settings).

While there are no hard and fast rules here, in general I would recommend [following the Elastic Common Schema](https://www.elastic.co/guide/en/ecs/current/ecs-base.html), which suggests a `@timestamp` field that is an ISO 8601 date string.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 18, 2020, 8:46pm UTC](https://discuss.elastic.co/t/format-for-timestamps/252878/3 "2020-11-18T20:46:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
