# Historic tomcat access logs transform historic timestamp to @timestamp

**URL:** <https://discuss.elastic.co/t/historic-tomcat-access-logs-transform-historic-timestamp-to-timestamp/325862>\
**Category:** Logstash\
**Created:** [February 17, 2023, 4:31pm UTC](https://discuss.elastic.co/t/historic-tomcat-access-logs-transform-historic-timestamp-to-timestamp/325862 "2023-02-17T16:31:19Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 17, 2023, 5:14pm UTC](https://discuss.elastic.co/t/historic-tomcat-access-logs-transform-historic-timestamp-to-timestamp/325862/3 "2023-02-17T17:14:56Z")

</div>

Use a date filter

```
 date { match => ["timestamp", "dd/MMM/YYYY:HH:mm:ss Z"] }

```

will result in

```
"@timestamp" => 2022-12-23T03:13:55.000Z,
 "timestamp" => "23/Dec/2022:04:13:55 +0100"

```

For the index, you could set the index option on the output to "access\_%{+YYYY.MM.dd}", but see [here](https://discuss.elastic.co/t/logstash-pipeline-index-question/325273/8) for why I do not think that is a good idea.

---

_[View the full topic](https://discuss.elastic.co/t/historic-tomcat-access-logs-transform-historic-timestamp-to-timestamp/325862)._
