# How to compare dates without timestamp

**URL:** <https://discuss.elastic.co/t/how-to-compare-dates-without-timestamp/170102>\
**Category:** Logstash\
**Created:** [February 27, 2019, 5:43am UTC](https://discuss.elastic.co/t/how-to-compare-dates-without-timestamp/170102 "2019-02-27T05:43:04Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![adityaPsl](https://avatars.discourse-cdn.com/v4/letter/a/e47c2d/32.png) [@adityaPsl](https://discuss.elastic.co/u/adityaPsl)\
**Post date:** [February 27, 2019, 5:43am UTC](https://discuss.elastic.co/t/how-to-compare-dates-without-timestamp/170102/1 "2019-02-27T05:43:04Z")

</div>

Hello Team,

I want to compare dates with @timestamp , but I don't want to compare the time , only the date part I want to compare.

I tried using date filter but could not set date in dd/MM/YY format

any pointers to resolve the issue are really appreciated.

Thank you,  
Aditya

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [February 27, 2019, 10:59am UTC](https://discuss.elastic.co/t/how-to-compare-dates-without-timestamp/170102/2 "2019-02-27T10:59:59Z")

</div>

Hi @adityaPsl,

you could try using something like `%{+YYYY.MM.dd}` which e.g. I use for daily index naming

Add this filter (edit to taste)

```
filter {
  mutate {
    add_field => { "foo_date" => "%{+YYYY.MM.dd}" }
  }
}

```

Then you can compare the field `foo_date`

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [February 27, 2019, 11:04am UTC](https://discuss.elastic.co/t/how-to-compare-dates-without-timestamp/170102/3 "2019-02-27T11:04:28Z")

</div>

This is the best [documentation](https://www.elastic.co/guide/en/logstash/6.7/plugins-inputs-beats.html#plugins-inputs-beats-versioned-indexes) I can quickly find...

> `%{+YYYY.MM.dd}`
> 
> Sets the third part of the name to a date based on the Logstash `@timestamp` field.

---

<div class="post-metadata">

**Author:** ![adityaPsl](https://avatars.discourse-cdn.com/v4/letter/a/e47c2d/32.png) [@adityaPsl](https://discuss.elastic.co/u/adityaPsl)\
**Post date:** [February 28, 2019, 6:18am UTC](https://discuss.elastic.co/t/how-to-compare-dates-without-timestamp/170102/4 "2019-02-28T06:18:54Z")

</div>

Thank you for your response A\_B. it helps.

Could you please let me know if There is a way to convert the date which is coming as date time field (dd/MM/yyyy HH:MM:SS) to date field with 'dd/mm/yyyy' format.

Thank you,  
Aditya

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [February 28, 2019, 8:05am UTC](https://discuss.elastic.co/t/how-to-compare-dates-without-timestamp/170102/5 "2019-02-28T08:05:06Z")

</div>

I think `%{+dd/MM/YYYY}` sould do the trick. Did not test though... As long as the date was initially parsed correctly and is in the `@timestamp` field.

If the original timestamp is to be extracted from some other field, you can use the [date filter](https://www.elastic.co/guide/en/logstash/6.6/plugins-filters-date.html).

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 28, 2019, 4:14pm UTC](https://discuss.elastic.co/t/how-to-compare-dates-without-timestamp/170102/6 "2019-02-28T16:14:49Z")

</div>

You can discard everything except the date using mutate+gsub, then parse it using a date filter.

```
mutate { gsub => ["field", "^([0-9]{2}/[0-9]{2}/[0-9]{4}).*", "\1" ] }
```

---

<div class="post-metadata">

**Author:** ![adityaPsl](https://avatars.discourse-cdn.com/v4/letter/a/e47c2d/32.png) [@adityaPsl](https://discuss.elastic.co/u/adityaPsl)\
**Post date:** [February 28, 2019, 5:07pm UTC](https://discuss.elastic.co/t/how-to-compare-dates-without-timestamp/170102/7 "2019-02-28T17:07:01Z")

</div>

Thank you very much A\_B and Badger,  
really appreciate the help.

i was able to extract the numbers but , could not find the option in date filter to set the format for target field. if i scan the field from date filter it again converts date in datetime format.

one more query  
can we convert date from one timestamp to another for example UTC to GMT.

Thank you very much for your help and support.

Thank you,  
Aditya

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 28, 2019, 5:20pm UTC](https://discuss.elastic.co/t/how-to-compare-dates-without-timestamp/170102/8 "2019-02-28T17:20:01Z")

</div>

All timestamps in elasticsearch are stored in UTC. Kibana will, by default, convert them to your local timezone.

---

<div class="post-metadata">

**Author:** ![adityaPsl](https://avatars.discourse-cdn.com/v4/letter/a/e47c2d/32.png) [@adityaPsl](https://discuss.elastic.co/u/adityaPsl)\
**Post date:** [March 1, 2019, 1:05am UTC](https://discuss.elastic.co/t/how-to-compare-dates-without-timestamp/170102/9 "2019-03-01T01:05:31Z")

</div>

Ok..but while comparing dates in logstash , I will need to convert dates to some common timezone. and dates coming from source are on different timezones.  
So two requirements

1. Convert dates to common timezone
2. Compare only the date part

Thank you for your help and support.

Thank you,  
Aditya

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 1, 2019, 1:32am UTC](https://discuss.elastic.co/t/how-to-compare-dates-without-timestamp/170102/10 "2019-03-01T01:32:07Z")

</div>

I you have a pattern in the events that allows you to check whether a particular format should apply then check for that pattern in the event. Otherwise use the same pattern.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2019, 1:35am UTC](https://discuss.elastic.co/t/how-to-compare-dates-without-timestamp/170102/11 "2019-03-29T01:35:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
