# How to replace @timestamp with logtime?

**URL:** <https://discuss.elastic.co/t/how-to-replace-timestamp-with-logtime/118949>\
**Category:** Logstash\
**Created:** [February 8, 2018, 12:29am UTC](https://discuss.elastic.co/t/how-to-replace-timestamp-with-logtime/118949 "2018-02-08T00:29:18Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![MichaelKutsenko](https://avatars.discourse-cdn.com/v4/letter/m/a8b319/32.png) [@MichaelKutsenko](https://discuss.elastic.co/u/MichaelKutsenko)\
**Post date:** [February 8, 2018, 12:29am UTC](https://discuss.elastic.co/t/how-to-replace-timestamp-with-logtime/118949/1 "2018-02-08T00:29:18Z")

</div>

I've read a lot of topics about this but I did not manage with this task. Please, help.  
I'm using filebeat, logstash, elasticsearch and kibana to show my logs. Client and server run on Ubuntu 16.04. When I try to replace @timestamp with logtime all new logs disappear but everything works good without "date" filter or if the date-pattern is wrong (in last case @timestamp shows time when message was received).

Log example:

`2018-02-07 18:08:15.717 DEBUG 2341 --- [nio-8080-exec-9] company.controller.MyController : some log message : hello`

nput config file 02-beats-input.conf:

```
input {
  beats {
    port => 5044
  }
}

```

filter config file: 10-java-filter.conf

```
filter {
  if [type] == "java" {
    grok {
      match => { "message" => "%{TIMESTAMP_ISO8601:logtime} %{LOGLEVEL:level} \[%{DATA:thread}\] %{JAVACLASS:class} %{GREEDYDATA:message}" }
      add_field => ["received_at", "%{@timestamp}"]
      overwrite => ["message"]
      remove_field => ["host", "count", "fields", "@version", "input_type", "offset", "source", "tags", "type"]
  }

  date {
    match => ["logtime", "yyyy-MM-dd HH:mm:ss.SSS"]
    target => "@timestamp"
    locale => "en"
    timezone => "UTC"
  }
}

```

30-elasticsearch-output.conf:

```
output {
  elasticsearch {
    hosts => ["localhost:9200"]
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
  }
}
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 8, 2018, 2:49am UTC](https://discuss.elastic.co/t/how-to-replace-timestamp-with-logtime/118949/2 "2018-02-08T02:49:02Z")

</div>

> [@MichaelKutsenko](#):
>
> When I try to replace @timestamp with logtime all new logs disappear but everything works good without "date" filter

Do all logs contain the `logtime` field?

---

<div class="post-metadata">

**Author:** ![Anuar\_Mukatov](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@Anuar\_Mukatov](https://discuss.elastic.co/u/Anuar_Mukatov)\
**Post date:** [February 8, 2018, 3:37am UTC](https://discuss.elastic.co/t/how-to-replace-timestamp-with-logtime/118949/3 "2018-02-08T03:37:07Z")

</div>

Try this -

```
filter {
    mutate {
	add_field => { "message" => "%{typenameru}" }
        convert => ["datetime", "string"]
}
date {
    timezone => "Etc/UTC"
    match => ["datetime" , "ISO8601", "yyyy-MM-dd HH:mm:ss.SSS"]
    target => "@timestamp"
    remove_field => ["datetime", "timestamp"]
}
}

```

For me it is helped.

---

<div class="post-metadata">

**Author:** ![MichaelKutsenko](https://avatars.discourse-cdn.com/v4/letter/m/a8b319/32.png) [@MichaelKutsenko](https://discuss.elastic.co/u/MichaelKutsenko)\
**Post date:** [February 8, 2018, 7:32am UTC](https://discuss.elastic.co/t/how-to-replace-timestamp-with-logtime/118949/4 "2018-02-08T07:32:49Z")

</div>

yes. All my logs have the same pattern as the first example.  
`2018-02-07 18:08:15.717 DEBUG 2341 --- [nio-8080-exec-9] company.controller.MyController : some log message : hello`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 8, 2018, 7:33am UTC](https://discuss.elastic.co/t/how-to-replace-timestamp-with-logtime/118949/5 "2018-03-08T07:33:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
