# How to change the @timestamp format in the Filebeat

**URL:** <https://discuss.elastic.co/t/how-to-change-the-timestamp-format-in-the-filebeat/361575>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 17, 2024, 10:18am UTC](https://discuss.elastic.co/t/how-to-change-the-timestamp-format-in-the-filebeat/361575 "2024-06-17T10:18:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Greeshma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/greeshma1/32/124990_2.png) [@Greeshma1](https://discuss.elastic.co/u/Greeshma1)\
**Post date:** [June 17, 2024, 10:18am UTC](https://discuss.elastic.co/t/how-to-change-the-timestamp-format-in-the-filebeat/361575/1 "2024-06-17T10:18:52Z")

</div>

I configured below processor to change the @timestamp format.

```auto
        processors:
          - timestamp:
              field: '@timestamp'
              layouts:
                - '2006-01-02T15:04:05.999+07:00'

```

Filebeat logs are @timestamp format as2024-06-17T11:50:11.689+0300 but need to change the format to this 2024-06-17T11:50:11.689+03:00 is there any alternative approached .

when I was using this processor i was seen below log  
{"log.level":"debug","@timestamp":"2024-06-17T11:50:11.689+0300","log.logger":"processor.timestamp","log.origin":{"function":"github.com/elastic/beats/v7/libbeat/processors/timestamp.(\*processor).parseValue","file.name":"timestamp/timestamp.go","file.line":152},"message":"Failure parsing time field.","service.name":"filebeat","error":{"message":"failed parsing time field json.@timestamp='2024-06-17T11:50:07.686+0300'","cause":[{"message":"failed using layout [2006-01-02T15:04:05.999-07:00] cannot parse [+0300] as [-07:00]"}]},"ecs.version":"1.6.0"}",

Thanks In advance

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 17, 2024, 12:26pm UTC](https://discuss.elastic.co/t/how-to-change-the-timestamp-format-in-the-filebeat/361575/2 "2024-06-17T12:26:46Z")

</div>

The `timestamp` processor is used to **parse** a timestamp field, not to change the format of the `@timestamp` field.

I don't think you can change the format that filebeat uses to write the `@timestamp` field.

---

<div class="post-metadata">

**Author:** ![ashishtiwari1993](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashishtiwari1993/32/135241_2.png) [@ashishtiwari1993](https://discuss.elastic.co/u/ashishtiwari1993)\
**Post date:** [June 17, 2024, 1:42pm UTC](https://discuss.elastic.co/t/how-to-change-the-timestamp-format-in-the-filebeat/361575/3 "2024-06-17T13:42:19Z")

</div>

Hi @Greeshma1 Welcome to Elastic community.

You can change it using `timestamp` and `convert` processor.

```auto
  - timestamp:
      field: "@timestamp"
      layouts:
        - '2006-01-02T15:04:05.000Z'
      test:
        - '2023-06-15T16:35:17.123Z'
  - convert:
      fields:
        - {from: "@timestamp", to: "@timestamp", type: string}

```

But i would suggest to store required format on another field.
