# Get timestamp from log lines

**URL:** <https://discuss.elastic.co/t/get-timestamp-from-log-lines/117816>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 31, 2018, 1:49pm UTC](https://discuss.elastic.co/t/get-timestamp-from-log-lines/117816 "2018-01-31T13:49:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tkzv](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tkzv/32/57319_2.png) [@tkzv](https://discuss.elastic.co/u/tkzv)\
**Post date:** [January 31, 2018, 1:49pm UTC](https://discuss.elastic.co/t/get-timestamp-from-log-lines/117816/1 "2018-01-31T13:49:09Z")

</div>

I'm using Filebeat to read logs in two different formats. Each portion of information is prefixed with timestamp in either "YYYYMMDD-hhmmss" or "MM.DD.YY hh:mm:ss" format. I use 2 different prospectors to merge lines for those 2 formats.

Sometimes the files are locked and Filebeat reads them only hours later. Is there a way to use these timestamps instead of the current time when data is added to Elasticsearch?

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [January 31, 2018, 3:11pm UTC](https://discuss.elastic.co/t/get-timestamp-from-log-lines/117816/2 "2018-01-31T15:11:16Z")

</div>

@tkzv Yes, we always recommend to correctly parse the date from the original string so the event is accurate. There are a few options to do that.

1. Check if your log format (or application) that you are parsing is one of our [supported modules](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-modules-overview.html), module is preconfigured prospectors that also include logic to parse the date correctly.

2. If you are sending your events directly to Elasticsearch, you can use the [ingest pipeline](https://www.elastic.co/guide/en/elasticsearch/reference/master/ingest.html) to configure some logic on the ES side to parse the event correctly. You may want to look at these processors: [grok](https://www.elastic.co/guide/en/elasticsearch/reference/master/grok-processor.html) and [date](https://www.elastic.co/guide/en/elasticsearch/reference/master/date-processor.html), You will also need to configure the [filebeat output to send to the correct pipeline](https://www.elastic.co/guide/en/beats/filebeat/current/configuring-ingest-node.html).

3. If you send your events through [Logstash](https://www.elastic.co/products/logstash), you can also use the [grok filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html) and the [date filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html)

---

<div class="post-metadata">

**Author:** ![tkzv](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tkzv/32/57319_2.png) [@tkzv](https://discuss.elastic.co/u/tkzv)\
**Post date:** [January 31, 2018, 3:31pm UTC](https://discuss.elastic.co/t/get-timestamp-from-log-lines/117816/3 "2018-01-31T15:31:18Z")

</div>

> Check if your log format (or application) that you are parsing is one of our supported modules,

It isn't.

> If you are sending your events directly to Elasticsearch,  
> If you send your events through Logstash,

I'm not using Logstash. Does it have any advantages for this task?

> You may want to look at these processors: grok and date, You will also need to configure the filebeat output to send to the correct pipeline.

I tried date earlier, when I was using only one prospector for "YYYYMMDD-hhmmss" format. For some reason it didn't work, and I reverted to defaults. What changes do I need to make to the example here [Date processor | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/date-processor.html) ? Would it be enough to change the "formats" line to `"formats" : ["YYYYMMDD-hhmmss"],` ?

P.S. Note to self: Joda format specification says it should be "yyyyMMdd-HHmmss".

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [January 31, 2018, 3:38pm UTC](https://discuss.elastic.co/t/get-timestamp-from-log-lines/117816/4 "2018-01-31T15:38:13Z")

</div>

@tkzv For what you are trying to achieve, the ingest pipeline would be enough. Logstash offers more inputs/processor than the ingest pipeline.

The [patterns](https://www.elastic.co/guide/en/elasticsearch/reference/master/date-processor.html) are using the [Joda syntax](http://www.joda.org/joda-time/apidocs/org/joda/time/format/DateTimeFormat.html), I believe in your case you want `yyyyMMdd-hhmmss`, the date processor accepts a list of patterns, it will return the value of the first one that correctly parses the date.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 28, 2018, 3:38pm UTC](https://discuss.elastic.co/t/get-timestamp-from-log-lines/117816/5 "2018-02-28T15:38:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
