# Functionbeat not using timestamp from CloudWatch logEvent

**URL:** <https://discuss.elastic.co/t/functionbeat-not-using-timestamp-from-cloudwatch-logevent/183551>\
**Category:** Beats\
**Tags:** functionbeat\
**Created:** [May 30, 2019, 2:20pm UTC](https://discuss.elastic.co/t/functionbeat-not-using-timestamp-from-cloudwatch-logevent/183551 "2019-05-30T14:20:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sparrowt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sparrowt/32/47163_2.png) [@sparrowt](https://discuss.elastic.co/u/sparrowt)\
**Post date:** [May 30, 2019, 2:20pm UTC](https://discuss.elastic.co/t/functionbeat-not-using-timestamp-from-cloudwatch-logevent/183551/1 "2019-05-30T14:20:36Z")

</div>

The CloudwatchLogs transformer in functionbeat (see [here](https://github.com/elastic/beats/blob/master/x-pack/functionbeat/provider/aws/transformer/transformer.go#L22-L27)) is using `time.Now()` for the `Timestamp` field (ends up as `@timestamp` in Elasticsearch) rather than extracting the `'timestamp'` field from the CloudWatch event, which is there alongside the `'message'`.

This means the `@timestamp` in Elasticsearch is a variable number of seconds later than the actual time the log line was sent to CloudWatch, which is not helpful.

Is there any reason the code in the TODO cannot be uncommented?

```
Timestamp: time.Now(), // TODO: time.Unix(logEvent.Timestamp, 0),

```

As per the [contributing guidelines](https://github.com/elastic/beats/blob/master/CONTRIBUTING.md) I am asking here before filing an issue in GitHub.

Many thanks.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [June 3, 2019, 8:05am UTC](https://discuss.elastic.co/t/functionbeat-not-using-timestamp-from-cloudwatch-logevent/183551/2 "2019-06-03T08:05:20Z")

</div>

Please file an issue on GH. Thank you for reporting it and following the guidelines. 🙂

---

<div class="post-metadata">

**Author:** ![sparrowt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sparrowt/32/47163_2.png) [@sparrowt](https://discuss.elastic.co/u/sparrowt)\
**Post date:** [June 4, 2019, 10:12am UTC](https://discuss.elastic.co/t/functionbeat-not-using-timestamp-from-cloudwatch-logevent/183551/3 "2019-06-04T10:12:19Z")

</div>

Thank you, filed here: [https://github.com/elastic/beats/issues/12412](https://github.com/elastic/beats/issues/12412)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 25, 2019, 12:20am UTC](https://discuss.elastic.co/t/functionbeat-not-using-timestamp-from-cloudwatch-logevent/183551/4 "2019-06-25T00:20:19Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
