# Grok timestamp field

**URL:** <https://discuss.elastic.co/t/grok-timestamp-field/33883>\
**Category:** Logstash\
**Created:** [November 5, 2015, 3:25pm UTC](https://discuss.elastic.co/t/grok-timestamp-field/33883 "2015-11-05T15:25:48Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![beorn107](https://avatars.discourse-cdn.com/v4/letter/b/a587f6/32.png) [@beorn107](https://discuss.elastic.co/u/beorn107)\
**Post date:** [November 5, 2015, 3:25pm UTC](https://discuss.elastic.co/t/grok-timestamp-field/33883/1 "2015-11-05T15:25:48Z")

</div>

Hi

I am trying to import a JSON file into ElasticSearch to use with Kibana. I am able to pull the file into ElasticSearch using Logstash but I am getting stuck on this one issue.

The json has the timestamp for the record as:

"Timestamp": "/Date(1446528260196-0500)/"

Is there a way I can use Grok to parse that field and convert the time so it will serve as a recognized timestamp field in my ElasticSearch index? Unfortunately I am not familiar with Grok at all so I am at a loss here.

Below is an example of the JSON.

Thanks for any help you can provide.

{ "LineNumber": 0, "SqlServerName": null, "SqlErrorNumber": 0, "SqlErrorMessage": null, "SqlProcedure": null, "SqlLineNumber": 0, "LogInformation": { "ServiceType": 1, "ServiceMethod": null, "HttpMethod": 0, "StatusCode": 404, "Controller": "carriercred", "Action": null, "TransactionResultCode": null, "ElapsedTime": "00:00:00.0178840", "PartnerId": null, "OrderId": null, "CarrierId": null, "MessageId": null }, "HttpStatusCode": 404, "HttpMethod": "Get", "Controller": "carriercred", "Action": null, "ServiceMethod": null, "ServiceType": "Rest", "ElapsedMs": 17.884, "LogLevel": "Info", "HostName": "", "ServerIP": "::1", "MethodName": "b\_\_0", "ExceptionMethodName": null, "ExceptionTypeFullName": null, "StackTrace": null, "LogMessage": "GET /secapi/carriercred/876ca42065c64067af5dc2532c3625d1 404", "Timestamp": "/Date(1446528260196-0500)/", "AdditionalData": null, "Namespace": "Service.Security.Http", "ClassName": "\<\>c\_\_DisplayClass3", "ProcessId": 6888, "ThreadId": 7, "CurrentIdentityName": "xxx", "CurrentIdentityAuthenticationType": "TrustedSubsystem", "IsCurrentIdentityAuthenticated": true, "SourceSystem": "ServiceSecurity", "ExceptionSource": null, "TransactionResultCode": null, "MessageType": "ServiceResult"}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 5, 2015, 3:40pm UTC](https://discuss.elastic.co/t/grok-timestamp-field/33883/2 "2015-11-05T15:40:24Z")

</div>

So this timestamp represents milliseconds since the epoch but in UTC-5 time rather than UTC which is customary for epochs? Sigh. The date filter can be used to parse millisecond epochs via the UNIX\_MS pattern but you may have to make the timezone adjustment via a ruby filter.

---

<div class="post-metadata">

**Author:** ![beorn107](https://avatars.discourse-cdn.com/v4/letter/b/a587f6/32.png) [@beorn107](https://discuss.elastic.co/u/beorn107)\
**Post date:** [November 5, 2015, 7:49pm UTC](https://discuss.elastic.co/t/grok-timestamp-field/33883/3 "2015-11-05T19:49:37Z")

</div>

If I don't care about the timezone adjustment is there a way to strip out the /Date( and -0500)/ and then do something like this:

filter {  
grok {  
mutate {  
strip =\> ["Timestamp"]  
}  
date {  
match =\> ["Timestamp", "UNIX"]  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 5, 2015, 8:24pm UTC](https://discuss.elastic.co/t/grok-timestamp-field/33883/4 "2015-11-05T20:24:35Z")

</div>

Sure, this should work:

```
grok {
  match => ["message", "\\/Date\(%{INT:epoch}-0500\)\\/"]
}
date {
  match => ["epoch", "UNIX_MS"]
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:23am UTC](https://discuss.elastic.co/t/grok-timestamp-field/33883/5 "2017-07-06T05:23:45Z")

</div>


