# How can I convert @timestamp from logstash to encoded format as YYYY-MM-DDThh:mm:ss.sss+/-hh:mm

**URL:** <https://discuss.elastic.co/t/how-can-i-convert-timestamp-from-logstash-to-encoded-format-as-yyyy-mm-ddthhss-sss-hh-mm/317608>\
**Category:** Logstash\
**Created:** [October 27, 2022, 11:28am UTC](https://discuss.elastic.co/t/how-can-i-convert-timestamp-from-logstash-to-encoded-format-as-yyyy-mm-ddthhss-sss-hh-mm/317608 "2022-10-27T11:28:17Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![teja\_tata](https://avatars.discourse-cdn.com/v4/letter/t/dec6dc/32.png) [@teja\_tata](https://discuss.elastic.co/u/teja_tata)\
**Post date:** [October 27, 2022, 11:28am UTC](https://discuss.elastic.co/t/how-can-i-convert-timestamp-from-logstash-to-encoded-format-as-yyyy-mm-ddthhss-sss-hh-mm/317608/1 "2022-10-27T11:28:17Z")

</div>

I have tried using date filter match option but didn't work.  
It would be great if someone can help me here.

---

<div class="post-metadata">

**Author:** ![cheshirecat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheshirecat/32/109532_2.png) [@cheshirecat](https://discuss.elastic.co/u/cheshirecat)\
**Post date:** [October 27, 2022, 12:06pm UTC](https://discuss.elastic.co/t/how-can-i-convert-timestamp-from-logstash-to-encoded-format-as-yyyy-mm-ddthhss-sss-hh-mm/317608/2 "2022-10-27T12:06:08Z")

</div>

And what is your filter syntax?

---

<div class="post-metadata">

**Author:** ![teja\_tata](https://avatars.discourse-cdn.com/v4/letter/t/dec6dc/32.png) [@teja\_tata](https://discuss.elastic.co/u/teja_tata)\
**Post date:** [October 27, 2022, 12:39pm UTC](https://discuss.elastic.co/t/how-can-i-convert-timestamp-from-logstash-to-encoded-format-as-yyyy-mm-ddthhss-sss-hh-mm/317608/3 "2022-10-27T12:39:41Z")

</div>

```auto
    date {
            match => ["timestamp", "ISO8601"]
            target => "@timestamp"
      }

```

Here "timestamp" is the variable where I want to store the converted timestamp

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 27, 2022, 1:58pm UTC](https://discuss.elastic.co/t/how-can-i-convert-timestamp-from-logstash-to-encoded-format-as-yyyy-mm-ddthhss-sss-hh-mm/317608/4 "2022-10-27T13:58:36Z")

</div>

Yes, this is how should code be in general.  
And how does your data look like? Can you give an example?

---

<div class="post-metadata">

**Author:** ![teja\_tata](https://avatars.discourse-cdn.com/v4/letter/t/dec6dc/32.png) [@teja\_tata](https://discuss.elastic.co/u/teja_tata)\
**Post date:** [October 27, 2022, 4:47pm UTC](https://discuss.elastic.co/t/how-can-i-convert-timestamp-from-logstash-to-encoded-format-as-yyyy-mm-ddthhss-sss-hh-mm/317608/5 "2022-10-27T16:47:18Z")

</div>

Here I am sending input message to logstash from filebeat and checking the message in Elasticsearch. There are few things I am trying to achieve here, like when we don't send any timestamp in input message then I will be taking "@timestamp" (timestamp at which logstash recieves the event)value and will convert to the format I want and save it in different field "timestamp".  
@timestamp we get from Logstash generally in this format "2022-10-27T03:49:25.530Z"  
I want new timestamp field with this format [YYYY-MM-DDThh:mm:ss.sss+/-hh:mm]

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 27, 2022, 5:19pm UTC](https://discuss.elastic.co/t/how-can-i-convert-timestamp-from-logstash-to-encoded-format-as-yyyy-mm-ddthhss-sss-hh-mm/317608/6 "2022-10-27T17:19:23Z")

</div>

> [@teja\_tata](#):
>
> I want new timestamp field with this format [YYYY-MM-DDThh:mm:ss.sss+/-hh:mm]

I don't think this is possible, using the date filter will transform the field into a date type field which will have this format `yyyy-MM-ddTHH:mm:ss.SSSZ` and the time will always be in UTC (that's waht the `Z` at the end means)

---

<div class="post-metadata">

**Author:** ![teja\_tata](https://avatars.discourse-cdn.com/v4/letter/t/dec6dc/32.png) [@teja\_tata](https://discuss.elastic.co/u/teja_tata)\
**Post date:** [October 27, 2022, 5:39pm UTC](https://discuss.elastic.co/t/how-can-i-convert-timestamp-from-logstash-to-encoded-format-as-yyyy-mm-ddthhss-sss-hh-mm/317608/7 "2022-10-27T17:39:13Z")

</div>

ok. Can you suggest me any other filter in Logstash or any logic with which I could achieve this conversion

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 27, 2022, 5:43pm UTC](https://discuss.elastic.co/t/how-can-i-convert-timestamp-from-logstash-to-encoded-format-as-yyyy-mm-ddthhss-sss-hh-mm/317608/8 "2022-10-27T17:43:02Z")

</div>

It depends, if you want the field to be a date field, then there is none, all date fields will have this format.

What you may try is to use some ruby code with the ruby filter to create a string with the format you want, but this will need to be mapped as a string in elasticsearch.

---

<div class="post-metadata">

**Author:** ![teja\_tata](https://avatars.discourse-cdn.com/v4/letter/t/dec6dc/32.png) [@teja\_tata](https://discuss.elastic.co/u/teja_tata)\
**Post date:** [October 27, 2022, 5:45pm UTC](https://discuss.elastic.co/t/how-can-i-convert-timestamp-from-logstash-to-encoded-format-as-yyyy-mm-ddthhss-sss-hh-mm/317608/9 "2022-10-27T17:45:18Z")

</div>

yeah in that case may be I can use date filter to convert that string after conversion to date again. Is that possible?

---

<div class="post-metadata">

**Author:** ![teja\_tata](https://avatars.discourse-cdn.com/v4/letter/t/dec6dc/32.png) [@teja\_tata](https://discuss.elastic.co/u/teja_tata)\
**Post date:** [October 27, 2022, 5:53pm UTC](https://discuss.elastic.co/t/how-can-i-convert-timestamp-from-logstash-to-encoded-format-as-yyyy-mm-ddthhss-sss-hh-mm/317608/10 "2022-10-27T17:53:17Z")

</div>

I have also found one similar issue attaching code solution and link below.

```auto
ruby {
        code => '
            t = Time.at(event.get("@timestamp").to_f)
            event.set("someField", t.strftime("%Y-%m-%d"))
        '
    }

```

> [@Date field being converted to timestamps](https://discuss.elastic.co/t/date-field-being-converted-to-timestamps/180044/3):
>
> Thanks for the reply. I though about change in it to string but couldnt do it, could you show me how? Also, so, there is no way to simple get my date values from the mysql and insert them just the way they are into es? Thanks a lot

But not sure how can I use this code to get the format I want [YYYY-MM-DDThh:mm:ss.sss+/-hh:mm]

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 27, 2022, 8:11pm UTC](https://discuss.elastic.co/t/how-can-i-convert-timestamp-from-logstash-to-encoded-format-as-yyyy-mm-ddthhss-sss-hh-mm/317608/11 "2022-10-27T20:11:58Z")

</div>

You want to add time offset to UTC? You can add as abs. like timezone =\> "+0100" or relatively to a time zone.

```auto
	date {
      match => ["timestamp", "ISO8601"]
      timezone => "Europe/Berlin"
	  target=> "@timestamp"
	}

```

---

<div class="post-metadata">

**Author:** ![teja\_tata](https://avatars.discourse-cdn.com/v4/letter/t/dec6dc/32.png) [@teja\_tata](https://discuss.elastic.co/u/teja_tata)\
**Post date:** [October 28, 2022, 1:50am UTC](https://discuss.elastic.co/t/how-can-i-convert-timestamp-from-logstash-to-encoded-format-as-yyyy-mm-ddthhss-sss-hh-mm/317608/12 "2022-10-28T01:50:18Z")

</div>

Here I don't want to change timezone I want offset as +00:00. Can I use the way you mentioned even for that case?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 25, 2022, 1:50am UTC](https://discuss.elastic.co/t/how-can-i-convert-timestamp-from-logstash-to-encoded-format-as-yyyy-mm-ddthhss-sss-hh-mm/317608/13 "2022-11-25T01:50:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
