# How to Change Date Format in Logstash

**URL:** <https://discuss.elastic.co/t/how-to-change-date-format-in-logstash/115603>\
**Category:** Logstash\
**Created:** [January 15, 2018, 8:59pm UTC](https://discuss.elastic.co/t/how-to-change-date-format-in-logstash/115603 "2018-01-15T20:59:38Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Saman.KH](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saman.kh/32/26590_2.png) [@Saman.KH](https://discuss.elastic.co/u/Saman.KH)\
**Post date:** [January 15, 2018, 8:59pm UTC](https://discuss.elastic.co/t/how-to-change-date-format-in-logstash/115603/1 "2018-01-15T20:59:39Z")

</div>

I use ELK 6.1.1 and File beat to send some applications log files to logstash.

Logstash automatically, try to changing some of my fields type to Date and this change is not suitable for me.

I need just numbers in date but logstash change month to the name of month like attached picture.

 ![57 AM](https://us1.discourse-cdn.com/elastic/original/3X/2/e/2e422f9357ff1401768665a42787cd3f739f6cba.png)  
For example it changes 1396/10/25 to October 25th 1396, which 1396 is year, 10 is month and 25 is day. It also add my time zone automatically and i want to remove it too.

Here is my configuration and sample data.

===============Logstash Config=================

```
input {
  beats {
    port => 5044
    #codec => plain { charset => "UTF-16" }
  }
}

filter {
	if [fields][log_type] == "dispatcher-packet"{
    csv {
        columns => ["PDate", "Date", "Time", "PacketSerial"]
        separator => "|"
        remove_field => ["host", "message", "path"]
    }
	mutate {
    convert => { "PacketSerial" => "integer" }
   }

output {

  if [fields][log_type] == "dispatcher-log"{
  elasticsearch { 
    hosts => ["localhost:9200"]
	index => "dispatcher-log-%{+YYYY.MM.dd}"
	}
}
  else if [fields][log_type] == "dispatcher-packet"{
  elasticsearch { 
    hosts => ["localhost:9200"]
	index => "dispatcher-packet4-%{+YYYY.MM.dd}"
	}
}
  stdout { codec => rubydebug }
}

```

=======================Sample File====================

```
PDate|Date|Time|PacketSerial
1396/10/25|2018-01-15|00:00:00.025|873672432

```

=======================get /dispatcher-packet4-2018.01.15============

```
{
  "dispatcher-packet4-2018.01.15": {
    "aliases": {},
    "mappings": {
      "doc": {
        "properties": {
          "@timestamp": {
            "type": "date"
          },
          "@version": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          
          "Date": {
            "type": "date"
          },
          
          "PDate": {
            "type": "date",
            "format": "yyyy/MM/dd HH:mm:ss||yyyy/MM/dd||epoch_millis"
       
          "PacketSerial": {
            "type": "long"
          },

          "Time": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
 
    "settings": {
      "index": {
        "creation_date": "1516043848975",
        "number_of_shards": "5",
        "number_of_replicas": "1",
        "uuid": "gNRUDFb5RxuWy7psju9-OA",
        "version": {
          "created": "6010199"
        },
        "provided_name": "dispatcher-packet4-2018.01.15"
      }
    }
  }
}

```

===============================================

What can i do?  
Many thanks in advance for your response.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 15, 2018, 9:14pm UTC](https://discuss.elastic.co/t/how-to-change-date-format-in-logstash/115603/2 "2018-01-15T21:14:34Z")

</div>

Please format your code using `</>` icon, it will make your post more readable and will help us help you 🙂

Alternatively use markdown style like this:

````
```
CODE
```
````

---

<div class="post-metadata">

**Author:** ![Saman.KH](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saman.kh/32/26590_2.png) [@Saman.KH](https://discuss.elastic.co/u/Saman.KH)\
**Post date:** [January 16, 2018, 8:36am UTC](https://discuss.elastic.co/t/how-to-change-date-format-in-logstash/115603/3 "2018-01-16T08:36:36Z")

</div>

Is it readable now?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 16, 2018, 8:57am UTC](https://discuss.elastic.co/t/how-to-change-date-format-in-logstash/115603/4 "2018-01-16T08:57:25Z")

</div>

Yes, thank you so much for that! 😃

Ok, so looking at all of that, it seems to be doing what it should be. Is `1396/10/25` not at date?

---

<div class="post-metadata">

**Author:** ![Saman.KH](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saman.kh/32/26590_2.png) [@Saman.KH](https://discuss.elastic.co/u/Saman.KH)\
**Post date:** [January 16, 2018, 9:44am UTC](https://discuss.elastic.co/t/how-to-change-date-format-in-logstash/115603/5 "2018-01-16T09:44:53Z")

</div>

**1396/10/25** is a date in Solar calendar.

---

<div class="post-metadata">

**Author:** ![Saman.KH](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saman.kh/32/26590_2.png) [@Saman.KH](https://discuss.elastic.co/u/Saman.KH)\
**Post date:** [January 16, 2018, 11:29am UTC](https://discuss.elastic.co/t/how-to-change-date-format-in-logstash/115603/6 "2018-01-16T11:29:15Z")

</div>

My problem is that Elasticsearch changes month which is a number "10" to month name "October". It's so useful that Elasticsearch changes my field to Date format, but I want only numbers. As I said before, our calendar is a Solar calendar and Elasticsearch uses a Gregorian calendar.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 16, 2018, 7:48pm UTC](https://discuss.elastic.co/t/how-to-change-date-format-in-logstash/115603/7 "2018-01-16T19:48:22Z")

</div>

That's not Elasticsearch, it's Kibana. Elasticsearch stores everything as UTC and then Kibana converts that to local, human readable time.

You may want to look at the advanced setting in Kibana called `dateFormat:scaled` to start.

---

<div class="post-metadata">

**Author:** ![Saman.KH](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saman.kh/32/26590_2.png) [@Saman.KH](https://discuss.elastic.co/u/Saman.KH)\
**Post date:** [January 19, 2018, 7:48am UTC](https://discuss.elastic.co/t/how-to-change-date-format-in-logstash/115603/8 "2018-01-19T07:48:13Z")

</div>

The problem is solved by changing the `dateFormat` on Kibana's advanced setting, from `MMMM Do YYYY, HH:mm:ss.SSS` to `MM Do YYY, HH:mm:ss.SSS`.

Tanks a lot.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 16, 2018, 7:48am UTC](https://discuss.elastic.co/t/how-to-change-date-format-in-logstash/115603/9 "2018-02-16T07:48:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
