# How to change the date structure to YYYY:MM:DD

**URL:** <https://discuss.elastic.co/t/how-to-change-the-date-structure-to-yyyydd/334789>\
**Category:** Logstash\
**Created:** [May 31, 2023, 11:08am UTC](https://discuss.elastic.co/t/how-to-change-the-date-structure-to-yyyydd/334789 "2023-05-31T11:08:41Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![subash\_k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/subash_k/32/121314_2.png) [@subash\_k](https://discuss.elastic.co/u/subash_k)\
**Post date:** [May 31, 2023, 11:08am UTC](https://discuss.elastic.co/t/how-to-change-the-date-structure-to-yyyydd/334789/1 "2023-05-31T11:08:41Z")

</div>

Hi,  
I tried multiple way to change the date event into YYYY:MMM:DD as log\_date. below format is actual date event (2023-05-31 10:30:50,244).  
I tried manual string concatenation even though am getting type as timestamp resulted as (2023-05-31 00:00:00.000) not as 2023-05-31.  
Thoughts ?  
TIA

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 31, 2023, 11:15am UTC](https://discuss.elastic.co/t/how-to-change-the-date-structure-to-yyyydd/334789/2 "2023-05-31T11:15:51Z")

</div>

Use ISO8601 instead of YYYY:MMM:DD

---

<div class="post-metadata">

**Author:** ![subash\_k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/subash_k/32/121314_2.png) [@subash\_k](https://discuss.elastic.co/u/subash_k)\
**Post date:** [May 31, 2023, 11:26am UTC](https://discuss.elastic.co/t/how-to-change-the-date-structure-to-yyyydd/334789/3 "2023-05-31T11:26:29Z")

</div>

Hello @Rios ,  
I tried below snippet

```auto
ruby {
  code => 'event.set("log_dates", event.get("date").gsub(/(\d{4}-\d{2}-\d{2}).*/, "\\1"))'
}

  ruby {
    code => '
      date_parts = event.get("date").split(" ")[0].split("-")
      event.set("year", date_parts[0])
      event.set("month", date_parts[1])
      event.set("day", date_parts[2])
      modified_date = "#{date_parts[0]}-#{date_parts[1]}-#{date_parts[2]}"
      event.set("modified_Date", modified_date)
    '
  }

mutate {
    convert => {
      "modified_Date" => "string"
    }
  }

```

input date event : **2023-05-31 10:30:48,841**  
Both log\_dates and modified\_Date returning like this -\> **2023-05-31 00:00:00.000**

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 31, 2023, 12:23pm UTC](https://discuss.elastic.co/t/how-to-change-the-date-structure-to-yyyydd/334789/4 "2023-05-31T12:23:12Z")

</div>

> [@subash\_k](#):
>
> I tried manual string concatenation even though am getting type as timestamp resulted as (2023-05-31 00:00:00.000) not as 2023-05-31

Where are you getting this result? It is in Logstash or in Elasticsearch? You didn't specify.

Elasticsearch per default will try to recognize a date if you do not have a explictily mapping for your index, and all date strings in Elasticsearch also needs a time, if the time is not provided it will be considered as 00:00 UTC.

If you want a date in Elasticsearch to looks like just `YYYY-MM-DD` you need to map this field as a string in your mapping before indexing anything.

---

<div class="post-metadata">

**Author:** ![subash\_k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/subash_k/32/121314_2.png) [@subash\_k](https://discuss.elastic.co/u/subash_k)\
**Post date:** [May 31, 2023, 12:57pm UTC](https://discuss.elastic.co/t/how-to-change-the-date-structure-to-yyyydd/334789/5 "2023-05-31T12:57:01Z")

</div>

> [@subash\_k](#):
>
> `modified_Date`

I tried converting to string for event modified\_Date that's also not working.  
While checking with logstash log am able to see **2023-05-31** but while checking in table (Index ) it's resulting as **2023-05-31 00:00:00.000**

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 31, 2023, 1:18pm UTC](https://discuss.elastic.co/t/how-to-change-the-date-structure-to-yyyydd/334789/6 "2023-05-31T13:18:44Z")

</div>

As I said in the previous answer, if you are seeing this in Elasticsearch you need to fix the mapping, it doesn't matter if you convert it to string or not in Logstash or if does not have a time, if you do not have a map for this field Elasticsearch will detect it as a date and will add the time.

You need to fix the mapping in Elasticsearch.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 28, 2023, 1:19pm UTC](https://discuss.elastic.co/t/how-to-change-the-date-structure-to-yyyydd/334789/7 "2023-06-28T13:19:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
