# How to create configure date filter data nested

**URL:** <https://discuss.elastic.co/t/how-to-create-configure-date-filter-data-nested/292273>\
**Category:** Logstash\
**Created:** [December 17, 2021, 8:11am UTC](https://discuss.elastic.co/t/how-to-create-configure-date-filter-data-nested/292273 "2021-12-17T08:11:15Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rizky\_Hudha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rizky_hudha/32/87736_2.png) [@Rizky\_Hudha](https://discuss.elastic.co/u/Rizky_Hudha)\
**Post date:** [December 17, 2021, 8:11am UTC](https://discuss.elastic.co/t/how-to-create-configure-date-filter-data-nested/292273/1 "2021-12-17T08:11:15Z")

</div>

I have some nested data in my log in the form of unix time, and I am trying to convert it to a time stamp, this is an example of the data I want to convert into a time stamp,

```auto
{
  "upstream_uri": "\/request",
   "route": {
         "response_buffering": true,
         "https_redirect_status_code": 426,
         "preserve_host": false,
         "strip_path": true,
        "created_at": 1629982852,
        "updated_at": 1629987382,
    }
}

```

And this my configuration

```auto

filter {
    date {
        match => ["[route,created_at]","UNIX_MS"]
    }
}

```

I've tried some changes in the date filter but still no change

---

<div class="post-metadata">

**Author:** ![Alex\_Marquardt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_marquardt/32/42925_2.png) [@Alex\_Marquardt](https://discuss.elastic.co/u/Alex_Marquardt)\
**Post date:** [December 17, 2021, 11:27am UTC](https://discuss.elastic.co/t/how-to-create-configure-date-filter-data-nested/292273/2 "2021-12-17T11:27:19Z")

</div>

I think your input json should not have a comma after the "udated\_at" line to be valid json. Also, the timestamp looks like it is not milliseconds. Also, you should modify the syntax for accessing the sub-object.

The following works:

```auto

  generator {
    lines => [
     '{"upstream_uri": "\/request", "route": {"created_at": 1629982852}}'
    ]
    count => 1
    codec => "json"

  }

}
filter {
    date {
        match => ["[route][created_at]","UNIX"]
        target => ["timestamp_created_at"]
    }
}

output {
  stdout { }
}

```

And creates the following output:

```auto
{
                "@version" => "1",
                   "route" => {
        "created_at" => 1629982852
    },
                    "host" => "New2020MacBook.lan",
                "sequence" => 0,
              "@timestamp" => 2021-12-17T11:24:25.506Z,
            "upstream_uri" => "/request",
    "timestamp_created_at" => 2021-08-26T13:00:52.000Z
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 14, 2022, 11:27am UTC](https://discuss.elastic.co/t/how-to-create-configure-date-filter-data-nested/292273/3 "2022-01-14T11:27:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
