# From Logdate generate @timestamp

**URL:** <https://discuss.elastic.co/t/from-logdate-generate-timestamp/124790>\
**Category:** Logstash\
**Created:** [March 20, 2018, 2:34pm UTC](https://discuss.elastic.co/t/from-logdate-generate-timestamp/124790 "2018-03-20T14:34:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Invictus](https://avatars.discourse-cdn.com/v4/letter/i/bc79bd/32.png) [@Invictus](https://discuss.elastic.co/u/Invictus)\
**Post date:** [March 20, 2018, 2:34pm UTC](https://discuss.elastic.co/t/from-logdate-generate-timestamp/124790/1 "2018-03-20T14:34:40Z")

</div>

Hi,

i have a problem concerning the @timestamp.  
So the timestamp should be the date from the logs and not the time filebeat read somthing into ELK.

Please find attached my Logs:

```
19.03.2018 19:50:55 Hostname : Message
19.03.2018 19:50:56 Hostname : Message
19.03.2018 19:50:56 Hostname : Message

```

My config from Logstash is the following:

```
filter {
        if [fields][LogEvent] == "Schnittstellen" {
                grok {
                        match => {"message" => "%{DATE:Datum} %{TIME:Uhrzeit} %{HOSTNAME:Hostname} :\ %{GREEDYDATA:message}"}
                        overwrite => ["message"]
                }
                date {
                        match => ["timestamp", ${DATE:Datum} ${TIME:Uhrzeit}]
                        target => ["@timestamp"]
                }
        }
}

```

I am trying to generate a timestamp from the fields DATE:Datum and TIME:Uhrzeit, but that seems to be bad formatting.

Thanks for some advice

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 20, 2018, 6:21pm UTC](https://discuss.elastic.co/t/from-logdate-generate-timestamp/124790/2 "2018-03-20T18:21:52Z")

</div>

Two problems:

- You're asking the date filter to parse a `timestamp` field but there is no such field.
- The date pattern is totally wrong.

Suggestion:

```auto
                grok {
                        match => {"message" => "^%{DATE:Datum} %{TIME:Uhrzeit} %{HOSTNAME:Hostname} :\ %{GREEDYDATA:message}"}
                        overwrite => ["message"]
                        add_field => {
                          "timestamp" => "%{Datum} %{Uhrzeit}"
                        }
                        remove_field => ["Datum", "Uhrzeit"]
                }
                date {
                        match => ["timestamp", "dd.MM.yyyy HH:mm:ss"]
                        target => ["@timestamp"]
                        remove_field => ["timestamp"]
                }

```

---

<div class="post-metadata">

**Author:** ![Invictus](https://avatars.discourse-cdn.com/v4/letter/i/bc79bd/32.png) [@Invictus](https://discuss.elastic.co/u/Invictus)\
**Post date:** [March 21, 2018, 6:57am UTC](https://discuss.elastic.co/t/from-logdate-generate-timestamp/124790/3 "2018-03-21T06:57:08Z")

</div>

Thats the solution, thanks a lot.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 18, 2018, 6:57am UTC](https://discuss.elastic.co/t/from-logdate-generate-timestamp/124790/4 "2018-04-18T06:57:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
