# How to read two different timestamp

**URL:** https://discuss.elastic.co/t/how-to-read-two-different-timestamp/167410
**Category:** Logstash
**Created:** [February 7, 2019, 9:46am UTC](https://discuss.elastic.co/t/how-to-read-two-different-timestamp/167410 "2019-02-07T09:46:01Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Sripal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sripal/32/36704_2.png) [@Sripal](https://discuss.elastic.co/u/Sripal)
#### Post date: [February 7, 2019, 9:46am UTC](https://discuss.elastic.co/t/how-to-read-two-different-timestamp/167410/1 "2019-02-07T09:46:01Z")

</div>

Hi,

I am getting issue while indexing the data

**My Log file :**  
**2019-01-02 14:31:02** [00000001] info [native] Apache reports revision 2.2.8()  
**2019-01-02 14:31:02** [00000001] info [native] Apache reports version string (irrelevant for dtagent)  
**2019-01-02 14:31:02** [00000001] info [native] =\> Detected Apache version 2.2  
**[Wed Jan 02 14:31:03 2019]** [notice] ---------------------------------------------------  
**[Wed Jan 02 14:31:03 2019]** [notice] Using config  
**[Wed Jan 02 14:31:03 2019]** [notice] foo bar

I have two different timestamp in my log file how do i index with same timestamp.

While creating an index pattern am getting two different pattern like **@timestamp** and **date**

How do i merge the date with timestamp.

**Here is my config file**

if[message] =~ /^20\*/ {   
grok { match =\>{   
"message" =\> "%{URIHOST:date} %{TIME:time} %{NAGIOSTIME:err\_number} %{CISCO\_REASON:loginfo}%{SYSLOG5424SD:native} %{GREEDYDATA:error\_msg}"

if[message] =~ /^[.\*/ {  
grok { match =\>{  
"message" =\> "%{SYSLOG5424SD:logtime} %{SYSLOG5424SD:info}"  
date {  
match =\> ["logtime" , "[EEE MMM dd HH:mm:ss yyyy]" ]  
target =\> "@timestamp"  
}

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [February 7, 2019, 2:33pm UTC](https://discuss.elastic.co/t/how-to-read-two-different-timestamp/167410/2 "2019-02-07T14:33:53Z")

</div>

I would use dissect rather than grok.

```
    if [message] =~ /^\[/ {
        dissect { mapping => { "message" => "[%{ts} %{+ts} %{+ts} %{+ts} %{+ts}] [%{level}] %{restOfLine}" } }
    } else {
        dissect { mapping => { "message" => "%{ts} %{+ts} [%{loginfo}] %{level} [%{native}] %{restOfLine}" } }
    }
    date { match => ["ts", "YYYY-MM-dd HH:mm:ss", "EEE MMM dd HH:mm:ss YYYY"] }
```

---

<div class="post-metadata">

### Author: ![Sripal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sripal/32/36704_2.png) [@Sripal](https://discuss.elastic.co/u/Sripal)
#### Post date: [February 8, 2019, 6:07am UTC](https://discuss.elastic.co/t/how-to-read-two-different-timestamp/167410/3 "2019-02-08T06:07:40Z")

</div>

@badger  
Thank you for your help. Somehow i managed with grok itself.

**Updated config file**  
mutate {  
add\_field =\> {  
"logtime" =\> "%{date} %{time}"  
}  
remove\_field =\> ["date", "time"]  
}  
date {  
match =\> ["logtime" , "yyyy-MM-dd HH:mm:ss" , "[EEE MMM dd HH:mm:ss yyyy]" ]  
target =\> "@timestamp" }

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 8, 2019, 6:07am UTC](https://discuss.elastic.co/t/how-to-read-two-different-timestamp/167410/4 "2019-03-08T06:07:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
