# Get seconds from the timestamp and put the into separate field

**URL:** <https://discuss.elastic.co/t/get-seconds-from-the-timestamp-and-put-the-into-separate-field/35056>\
**Category:** Logstash\
**Created:** [November 19, 2015, 1:20pm UTC](https://discuss.elastic.co/t/get-seconds-from-the-timestamp-and-put-the-into-separate-field/35056 "2015-11-19T13:20:39Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![nkoleff](https://avatars.discourse-cdn.com/v4/letter/n/d9b06d/32.png) [@nkoleff](https://discuss.elastic.co/u/nkoleff)\
**Post date:** [November 19, 2015, 1:20pm UTC](https://discuss.elastic.co/t/get-seconds-from-the-timestamp-and-put-the-into-separate-field/35056/1 "2015-11-19T13:20:39Z")

</div>

Hello, I am trying to do the following:

If the field **mymessage** contains My string, create another field called seconds and put there the bolded value of my timestamp - November 15th 2015, 08:42: **29.779**. In other words I would like this to result in seconds=29.779 which is taken from the timestamp of the event, but unfortunately this puts value of %{SECOND}

 ![](https://us1.discourse-cdn.com/elastic/original/2X/5/5d067a13b98ac8e51a61836a56c5dd38106fc935.png)

if [mymessage] =~ /^My string/ {  
mutate {  
add\_field =\> ["seconds", "%{SECOND}"]  
}  
.....  
}

What am I doing wrong?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 19, 2015, 1:51pm UTC](https://discuss.elastic.co/t/get-seconds-from-the-timestamp-and-put-the-into-separate-field/35056/2 "2015-11-19T13:51:36Z")

</div>

I think you might be conflating grok patterns and fields. You get "%{SECOND}" because the messages doesn't have a field named `SECOND`.

Use a grok filter to extract the seconds from the `@timestamp` field. Untested:

```
grok {
  match => ["@timestamp", ":%{SECOND:seconds}Z"]
}
```

---

<div class="post-metadata">

**Author:** ![gauravkb](https://avatars.discourse-cdn.com/v4/letter/g/a4c791/32.png) [@gauravkb](https://discuss.elastic.co/u/gauravkb)\
**Post date:** [May 13, 2016, 9:22am UTC](https://discuss.elastic.co/t/get-seconds-from-the-timestamp-and-put-the-into-separate-field/35056/3 "2016-05-13T09:22:42Z")

</div>

how can i extract hours , minute and also weekday from timestamp..

---

<div class="post-metadata">

**Author:** ![LetMeR00t](https://avatars.discourse-cdn.com/v4/letter/l/9de0a6/32.png) [@LetMeR00t](https://discuss.elastic.co/u/LetMeR00t)\
**Post date:** [May 13, 2016, 9:43am UTC](https://discuss.elastic.co/t/get-seconds-from-the-timestamp-and-put-the-into-separate-field/35056/4 "2016-05-13T09:43:30Z")

</div>

You just have to find the pattern you want to use in grok, see here for available patterns :

[https://github.com/elastic/logstash/blob/v1.4.2/patterns/grok-patterns](https://github.com/elastic/logstash/blob/v1.4.2/patterns/grok-patterns)

---

<div class="post-metadata">

**Author:** ![gauravkb](https://avatars.discourse-cdn.com/v4/letter/g/a4c791/32.png) [@gauravkb](https://discuss.elastic.co/u/gauravkb)\
**Post date:** [May 13, 2016, 10:05am UTC](https://discuss.elastic.co/t/get-seconds-from-the-timestamp-and-put-the-into-separate-field/35056/5 "2016-05-13T10:05:53Z")

</div>

thank you so much for such a soon reply...  
i did manage to get the the hours , minute , sec from the timestamp..

But is there any possibility of geeting week day from the timestamp..

for example this is my timestamp "11/May/2016:05:00:00 +0530"  
how can i achieve the weekday from this ..  
like  
weekday:wednesday

thank you

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 13, 2016, 10:43am UTC](https://discuss.elastic.co/t/get-seconds-from-the-timestamp-and-put-the-into-separate-field/35056/6 "2016-05-13T10:43:16Z")

</div>

I don't think there's a plugin that'll do this for you, but you can definitely write some Ruby code and put in a ruby filter.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:56am UTC](https://discuss.elastic.co/t/get-seconds-from-the-timestamp-and-put-the-into-separate-field/35056/8 "2017-07-06T04:56:29Z")

</div>


