# I need to concatenate two fields one from date and the other from time and send to Elasticsearc 4.6.4

**URL:** <https://discuss.elastic.co/t/i-need-to-concatenate-two-fields-one-from-date-and-the-other-from-time-and-send-to-elasticsearc-4-6-4/158165>\
**Category:** Elasticsearch\
**Created:** [November 26, 2018, 11:26am UTC](https://discuss.elastic.co/t/i-need-to-concatenate-two-fields-one-from-date-and-the-other-from-time-and-send-to-elasticsearc-4-6-4/158165 "2018-11-26T11:26:15Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eduardo\_Bertolucci1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eduardo_bertolucci1/32/38050_2.png) [@Eduardo\_Bertolucci1](https://discuss.elastic.co/u/Eduardo_Bertolucci1)\
**Post date:** [November 26, 2018, 11:26am UTC](https://discuss.elastic.co/t/i-need-to-concatenate-two-fields-one-from-date-and-the-other-from-time-and-send-to-elasticsearc-4-6-4/158165/1 "2018-11-26T11:26:15Z")

</div>

Dear,

I need to concatenate two fields to send to Elasticsearc 4.6.4, one field is of date and the other field is time and that field is mapped automatically.

**Example of a txt file:**

0;0;0;0;0;ENTRADA;;;;;;09/06/2014;06:18:55.234;XXXX;XXXX;  
0;0;0;0;0;ENTRADA;;;;;;09/06/2014;06:18:55.284;XXXX;XXXX;

I want to concatenate the date + time field (09/06/2014;06:18:55.234).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 26, 2018, 11:59am UTC](https://discuss.elastic.co/t/i-need-to-concatenate-two-fields-one-from-date-and-the-other-from-time-and-send-to-elasticsearc-4-6-4/158165/2 "2018-11-26T11:59:36Z")

</div>

Could you please edit your question and ask in english?

---

<div class="post-metadata">

**Author:** ![Eduardo\_Bertolucci1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eduardo_bertolucci1/32/38050_2.png) [@Eduardo\_Bertolucci1](https://discuss.elastic.co/u/Eduardo_Bertolucci1)\
**Post date:** [November 26, 2018, 11:59am UTC](https://discuss.elastic.co/t/i-need-to-concatenate-two-fields-one-from-date-and-the-other-from-time-and-send-to-elasticsearc-4-6-4/158165/3 "2018-11-26T11:59:49Z")

</div>

Yes.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 26, 2018, 12:13pm UTC](https://discuss.elastic.co/t/i-need-to-concatenate-two-fields-one-from-date-and-the-other-from-time-and-send-to-elasticsearc-4-6-4/158165/4 "2018-11-26T12:13:37Z")

</div>

Great.

Note that Elasticsearch 4.6.4 does not exist. I assume you meant 6.4.x.

Have a look at [ingest pipelines](https://www.elastic.co/guide/en/elasticsearch/reference/6.5/ingest.html). That helps to modify the source document before it gets indexed.

May be this processor would help in your case? [https://www.elastic.co/guide/en/elasticsearch/reference/6.5/set-processor.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.5/set-processor.html)

---

<div class="post-metadata">

**Author:** ![Eduardo\_Bertolucci1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eduardo_bertolucci1/32/38050_2.png) [@Eduardo\_Bertolucci1](https://discuss.elastic.co/u/Eduardo_Bertolucci1)\
**Post date:** [November 26, 2018, 2:21pm UTC](https://discuss.elastic.co/t/i-need-to-concatenate-two-fields-one-from-date-and-the-other-from-time-and-send-to-elasticsearc-4-6-4/158165/5 "2018-11-26T14:21:11Z")

</div>

I need the join of the two fields to be the current time (timestamp).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 26, 2018, 2:33pm UTC](https://discuss.elastic.co/t/i-need-to-concatenate-two-fields-one-from-date-and-the-other-from-time-and-send-to-elasticsearc-4-6-4/158165/6 "2018-11-26T14:33:01Z")

</div>

Yes. That's what I understood. And exactly what I proposed I believe.

---

<div class="post-metadata">

**Author:** ![Eduardo\_Bertolucci1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eduardo_bertolucci1/32/38050_2.png) [@Eduardo\_Bertolucci1](https://discuss.elastic.co/u/Eduardo_Bertolucci1)\
**Post date:** [November 26, 2018, 3:08pm UTC](https://discuss.elastic.co/t/i-need-to-concatenate-two-fields-one-from-date-and-the-other-from-time-and-send-to-elasticsearc-4-6-4/158165/7 "2018-11-26T15:08:01Z")

</div>

I am using this configuration in .conf

filter {  
csv {  
separator =\> ";"  
columns =\> ["1","2","3","4","5","6","7","8","9","10","11","Data","Hora","14"]  
}  
mutate {  
add\_field =\> {  
"Data2" =\> "%{Data} %{Hora}"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 26, 2018, 3:28pm UTC](https://discuss.elastic.co/t/i-need-to-concatenate-two-fields-one-from-date-and-the-other-from-time-and-send-to-elasticsearc-4-6-4/158165/8 "2018-11-26T15:28:44Z")

</div>

This is logstash then. Ok. Does it work?

---

<div class="post-metadata">

**Author:** ![Eduardo\_Bertolucci1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eduardo_bertolucci1/32/38050_2.png) [@Eduardo\_Bertolucci1](https://discuss.elastic.co/u/Eduardo_Bertolucci1)\
**Post date:** [November 26, 2018, 4:10pm UTC](https://discuss.elastic.co/t/i-need-to-concatenate-two-fields-one-from-date-and-the-other-from-time-and-send-to-elasticsearc-4-6-4/158165/9 "2018-11-26T16:10:52Z")

</div>

> [@dadoonet](#):
>
> This is logstash then. Ok. Does it work?

It partially works.

I need these two fields to be sent with the date type.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 26, 2018, 4:33pm UTC](https://discuss.elastic.co/t/i-need-to-concatenate-two-fields-one-from-date-and-the-other-from-time-and-send-to-elasticsearc-4-6-4/158165/10 "2018-11-26T16:33:09Z")

</div>

> I need these two fields to be sent with the date type.

Either change the mapping in elasticsearch and set the format. See [Date field type | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/date.html)

Or send dates with this format (and they will get automatically detected): `2015-01-01T12:10:30Z`. Something like `%{Data}T%{Hora}`.

Or use a date filter in addition to this. See [Date filter plugin | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html)

HTH

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2018, 4:33pm UTC](https://discuss.elastic.co/t/i-need-to-concatenate-two-fields-one-from-date-and-the-other-from-time-and-send-to-elasticsearc-4-6-4/158165/11 "2018-12-24T16:33:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
