# How to add day of month field but with certain timezone

**URL:** <https://discuss.elastic.co/t/how-to-add-day-of-month-field-but-with-certain-timezone/349207>\
**Category:** Logstash\
**Created:** [December 13, 2023, 3:24am UTC](https://discuss.elastic.co/t/how-to-add-day-of-month-field-but-with-certain-timezone/349207 "2023-12-13T03:24:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [December 13, 2023, 3:24am UTC](https://discuss.elastic.co/t/how-to-add-day-of-month-field-but-with-certain-timezone/349207/1 "2023-12-13T03:24:33Z")

</div>

i want to create a "day of month" field for my visualization. I already did this using a scripted field before. but since I chose Grafana to visualize my data, I can't use that scripted field there. so I want to generate it from logstash; here is the script in kibana:

```auto
month:
ZonedDateTime pst = doc['process_timestamp.date_histogram.timestamp'].value.withZoneSameInstant(ZoneId.of('Asia/Jakarta')); return pst.getMonthValue();

day:
ZonedDateTime pst = doc['process_timestamp.date_histogram.timestamp'].value.withZoneSameInstant(ZoneId.of('Asia/Jakarta')); return pst.getDayOfMonth();

```

how do I do it if I want to create a day-of-month field with my timezone? i already tried this but I got UTC timezone

```auto
mutate {
 add_field => {"dayOfmonth" => "%{+dd-HH}"}
}

```

\*i added HH just to make sure what timezone is being used and I'm still working with date filter but has not yet found a solution

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 13, 2023, 3:55am UTC](https://discuss.elastic.co/t/how-to-add-day-of-month-field-but-with-certain-timezone/349207/2 "2023-12-13T03:55:37Z")

</div>

logstash [@timestamp] is always UTC, so "%{+dd-HH}" is always going to be UTC. You would need to use a ruby filter to apply the timezone offset.

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [December 13, 2023, 4:02am UTC](https://discuss.elastic.co/t/how-to-add-day-of-month-field-but-with-certain-timezone/349207/3 "2023-12-13T04:02:56Z")

</div>

thank you. finally i found this  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/f/3f1b8b312f47c5f3793362c7b9c894bc1d794aa8.png)

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [December 13, 2023, 4:26am UTC](https://discuss.elastic.co/t/how-to-add-day-of-month-field-but-with-certain-timezone/349207/4 "2023-12-13T04:26:41Z")

</div>

Yes, you have to use ruby because UTC which Badger mentioned.  
Another approach:

```auto
 ruby {
    code => "
	require 'tzinfo'
    current_time = Time.now
	timezone = TZInfo::Timezone.get(current_time.zone)
	timezone_name = timezone.name
	 event.set('[@metadata][tz]', timezone_name)
    "
  }
 
mutate { add_field => {"dayOfmonth" => "%{+dd-HH} %{[@metadata][tz]}"} }

```

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [December 13, 2023, 4:35am UTC](https://discuss.elastic.co/t/how-to-add-day-of-month-field-but-with-certain-timezone/349207/5 "2023-12-13T04:35:59Z")

</div>

I tried using your code, but I got this error in logstash:

```auto
 Ruby exception occurred: Invalid identifier: WIB {:class=>"TZInfo::InvalidTimezoneIdentifier"

```

and also in kibana, it gives me something like this  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/5/b547959fc49b5d0f46504619a1ec3db196ab148e.png)

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [December 13, 2023, 4:42am UTC](https://discuss.elastic.co/t/how-to-add-day-of-month-field-but-with-certain-timezone/349207/6 "2023-12-13T04:42:18Z")

</div>

You should use ruby in LS.

```auto
input {
  generator {
       message => "2023-11-25 15:51:46 DEBUG Request Approved"
	   count => 1
  }
} 

filter {

 ruby {
    code => "
	require 'tzinfo'
    current_time = Time.now
	timezone = TZInfo::Timezone.get(current_time.zone)
	timezone_name = timezone.name
	 event.set('[@metadata][tz]', timezone_name)
    "
  }
  
   	 mutate {
 add_field => {"dayOf" => "%{+dd-HH} %{[@metadata][tz]}"}
 remove_field => ["host", "event", "message"]
} 

  
}
output {
 stdout { codec => rubydebug{ metadata => false} }
}

```

Result in LS 8.11:

```auto
{
         "dayOf" => "13-04 CET",
      "@version" => "1",
    "@timestamp" => 2023-12-13T04:40:31.648947Z
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2024, 4:43am UTC](https://discuss.elastic.co/t/how-to-add-day-of-month-field-but-with-certain-timezone/349207/7 "2024-01-10T04:43:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
