# How to name new index based on time from log

**URL:** <https://discuss.elastic.co/t/how-to-name-new-index-based-on-time-from-log/73336>\
**Category:** Logstash\
**Created:** [January 31, 2017, 9:58am UTC](https://discuss.elastic.co/t/how-to-name-new-index-based-on-time-from-log/73336 "2017-01-31T09:58:46Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![John16](https://avatars.discourse-cdn.com/v4/letter/j/ea666f/32.png) [@John16](https://discuss.elastic.co/u/John16)\
**Post date:** [January 31, 2017, 9:58am UTC](https://discuss.elastic.co/t/how-to-name-new-index-based-on-time-from-log/73336/1 "2017-01-31T09:58:46Z")

</div>

Hello,

by default logstash names index using pattern logstash-%{+yyyy.MM.dd}  
(and filebeat-%{+yyyy.MM.dd} for filebeat), where %{+yyyy.MM.dd} is the date when event is being published to ES.

How can I substitute date taken from my log for %{+yyyy.MM.dd} ?

For example, if I load week's old log I want an index to have a name logstash-2017.01.24 rather than today's logstash-2017.01.31?

Thanks.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 31, 2017, 10:00am UTC](https://discuss.elastic.co/t/how-to-name-new-index-based-on-time-from-log/73336/2 "2017-01-31T10:00:08Z")

</div>

You need to use the date filter to do that match before it gets sent to the output. That way it'll use the correct event time in that pattern.

---

<div class="post-metadata">

**Author:** ![John16](https://avatars.discourse-cdn.com/v4/letter/j/ea666f/32.png) [@John16](https://discuss.elastic.co/u/John16)\
**Post date:** [January 31, 2017, 1:20pm UTC](https://discuss.elastic.co/t/how-to-name-new-index-based-on-time-from-log/73336/4 "2017-01-31T13:20:29Z")

</div>

Okay, it works, thanks!

But I am facing one small problem: I have date in the following format:  
2017-01-29T00:00:06

and this date is in local timezone (UTC+3). This timezone is correctly configured on server.

I have the following filter:  
date {  
match =\> ["date", "yyyy-MM-dd'T'HH:mm:ss"]  
}

But in kibana I see that logs corresponding to 00:00:06 time are displayed as 03:00:06. Addition of "timezone" parameter to date{} filter does not change things.

Also, log lines generated after 21:00 go to test-2017.01.${DAY+1} index, which is inconvenient.

What is the proper way to configure timezone so that Kibana correctly displays time and index =\> "test-%{+YYYY.MM.dd}" works as expected (MM.dd corresponds to my local time)?

It looks like Logstash does not honour my local timezone (it assumes time is already in UTC), but Kinaba then converts UTC to my localtime and I get 3 hours discrepancy.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 31, 2017, 8:14pm UTC](https://discuss.elastic.co/t/how-to-name-new-index-based-on-time-from-log/73336/5 "2017-01-31T20:14:15Z")

</div>

ES always stores in UTC.  
KB adjusts that to whatever TZ the browser is set as.  
LS also assumes UTC and then uses that when talking to ES, so the "rollover" time is 0000UTC.

---

<div class="post-metadata">

**Author:** ![John16](https://avatars.discourse-cdn.com/v4/letter/j/ea666f/32.png) [@John16](https://discuss.elastic.co/u/John16)\
**Post date:** [February 1, 2017, 5:41am UTC](https://discuss.elastic.co/t/how-to-name-new-index-based-on-time-from-log/73336/6 "2017-02-01T05:41:03Z")

</div>

Okay, this explains things. But what is the solution? How can I tell LS the actual TZ of my timestamp, so it correctly converts it to UTC?

Index names are not so important, but at least store correct time in my "date" field so that graphs at Kibana do not have 3 hours shift ahead of actual time.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 1, 2017, 7:08am UTC](https://discuss.elastic.co/t/how-to-name-new-index-based-on-time-from-log/73336/7 "2017-02-01T07:08:47Z")

</div>

> Okay, this explains things. But what is the solution? How can I tell LS the actual TZ of my timestamp, so it correctly converts it to UTC?

If the system's timezone isn't detected automatically use the date filter's `timezone` option.

---

<div class="post-metadata">

**Author:** ![John16](https://avatars.discourse-cdn.com/v4/letter/j/ea666f/32.png) [@John16](https://discuss.elastic.co/u/John16)\
**Post date:** [February 1, 2017, 7:37am UTC](https://discuss.elastic.co/t/how-to-name-new-index-based-on-time-from-log/73336/8 "2017-02-01T07:37:28Z")

</div>

As I already wrote in this thread, timezone is correctly configured on my computer and I tried to set timezone parameter directly. No success.

I used timezone value in formats "Asia/Qatar" and "Etc/GMT-3" according to  
[http://joda-time.sourceforge.net/timezones.html](http://joda-time.sourceforge.net/timezones.html)

Consider this log line:  
2017-01-29T00:00:06 189 200 127.0.0.1 GET /

and

date {  
match =\> ["date", "yyyy-MM-dd'T'HH:mm:ss"]  
timezone =\> "Etc/GMT-3"  
}

Logstash names index as test-2017.01.28 (28 because Jan 29 0:00 +003 is Jan 28 21:00 UTC).

But Kibana displays this line at 03:00 time.

In Time column: January 29th 2017, 03:00:06.000  
In \_source column: date:January 29th 2017, 03:00:06.000 offset:...  
Below in Table tab:  
@timestamp January 29th 2017, 00:00:06.000  
date January 29th 2017, 03:00:06.000

But in JSON tab:  
"\_source": {  
"date": "2017-01-29T00:00:06",

So looks like despite timezone =\> "Etc/GMT-3" ES still treats this time as 00:00 UTC rather that 00:00 Etc/GMT-3

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 1, 2017, 8:30am UTC](https://discuss.elastic.co/t/how-to-name-new-index-based-on-time-from-log/73336/9 "2017-02-01T08:30:02Z")

</div>

Unless you set `target => "date"` Logstash will store the parsed timestamp in the `@timestamp` field (which is the one used when expanding `%{+yyyy.MM.dd}`). AFAICT Logstash parses your timestamp and sets `@timestamp` correctly:

```nohighlight
[magnusbk@lnxolofon] /tmp/trash.vxiU$ cat test.config 
input { stdin { } }
output { stdout { codec => rubydebug } }
filter {
  date {
    match => ["message", "yyyy-MM-dd'T'HH:mm:ss"]
    timezone => "Etc/GMT-3"
  }
}
$ echo '2017-01-29T00:00:06' | /opt/logstash/bin/logstash -f test.config 
Settings: Default pipeline workers: 8
Pipeline main started
{
       "message" => "2017-01-29T00:00:06",
      "@version" => "1",
    "@timestamp" => "2017-01-28T21:00:06.000Z",
          "host" => "lnxolofon"
}
Pipeline main has been shutdown
stopping pipeline {:id=>"main"}

```

---

<div class="post-metadata">

**Author:** ![John16](https://avatars.discourse-cdn.com/v4/letter/j/ea666f/32.png) [@John16](https://discuss.elastic.co/u/John16)\
**Post date:** [February 1, 2017, 8:32am UTC](https://discuss.elastic.co/t/how-to-name-new-index-based-on-time-from-log/73336/10 "2017-02-01T08:32:53Z")

</div>

Aha, I see now.

How can I instruct logstash to update both @timestamp and "date" to adjust timezone? Can I use array as target value?  
target =\> ["date", "@timestamp"]

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 1, 2017, 8:37am UTC](https://discuss.elastic.co/t/how-to-name-new-index-based-on-time-from-log/73336/11 "2017-02-01T08:37:02Z")

</div>

No, you need two date filters.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 1, 2017, 8:37am UTC](https://discuss.elastic.co/t/how-to-name-new-index-based-on-time-from-log/73336/12 "2017-03-01T08:37:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
