# Inconsistent timestamp format from logstash out

**URL:** <https://discuss.elastic.co/t/inconsistent-timestamp-format-from-logstash-out/316568>\
**Category:** Logstash\
**Created:** [October 13, 2022, 6:27pm UTC](https://discuss.elastic.co/t/inconsistent-timestamp-format-from-logstash-out/316568 "2022-10-13T18:27:04Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![dchavan](https://avatars.discourse-cdn.com/v4/letter/d/a88e57/32.png) [@dchavan](https://discuss.elastic.co/u/dchavan)\
**Post date:** [October 13, 2022, 6:27pm UTC](https://discuss.elastic.co/t/inconsistent-timestamp-format-from-logstash-out/316568/1 "2022-10-13T18:27:04Z")

</div>

There seems to be some inconsistency in the way logstash @timestamp is added in the out file.

```auto
{"host":"X","version":"unknown","event":{"original":"2022-10-12T15:51:22,937 WARN [EAF11E629F8C4DF987673EAABE186797][scheduling-8] c.a.c.d.d.CertificateChangeMessagesDao: expect update count of 1, but get 0"},"message":"2022-10-12T15:51:22,937 WARN [EAF11E629F8C4DF987673EAABE186797][scheduling-8] c.a.c.d.d.CertificateChangeMessagesDao: expect update count of 1, but get 0","path":"/usr/logs/cpc-main-stdout.log","app":"cps","filename":"cps-main-stdout.log","ip_addr":"198.X.X.X","@timestamp":"2022-10-12T15:51:23Z"}
{"host":"X","version":"unknown","event":{"original":"2022-10-12T15:51:22,937 INFO [EAF11E629F8C4DF987673EAABE186797][scheduling-8] c.a.c.d.d.CertificateChangeMessagesDao: upsert updated 34930"},"message":"2022-10-12T15:51:22,937 INFO [EAF11E629F8C4DF987673EAABE186797][scheduling-8] c.a.c.d.d.CertificateChangeMessagesDao: upsert updated 34930","path":"/usr/logs/cpc-main-stdout.log","app":"cpc","filename":"cpc-main-stdout.log","ip_addr":"198.X.X.X","@timestamp":"2022-10-12T15:51:23.000015Z"}
{"host":"X","version":"unknown","event":{"original":"2022-10-12T15:51:22,937 INFO [EAF11E629F8C4DF987673EAABE186797][scheduling-8] c.a.c.d.s.GrimReaperService: processStalledJobs: certChangeMessagesIdFinal: 34930"},"message":"2022-10-12T15:51:22,937 INFO [EAF11E629F8C4DF987673EAABE186797][scheduling-8] c.a.c.d.s.GrimReaperService: processStalledJobs: certChangeMessagesIdFinal: 34930","path":"/usr/logs/cpc-main-stdout.log","app":"cpc","filename":"cpc-main-stdout.log","ip_addr":"198.X.X.X","@timestamp":"2022-10-12T15:51:23.000029Z"}

```

As seen above the @timestamp field has one value which is "2022-10-12T15:51:23Z" (discrepancy) and the rest are 2022-10-12T15:51:23.SSSZ.  
What could be the reason for this? Also, can using a ruby filter fix this? I would like to get some example config to have all the timestamps in "yyyy-MM-dd'T'HH:mm:ss.SSS'Z'" format.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 13, 2022, 7:58pm UTC](https://discuss.elastic.co/t/inconsistent-timestamp-format-from-logstash-out/316568/2 "2022-10-13T19:58:07Z")

</div>

How are you setting [@timestamp]?

---

<div class="post-metadata">

**Author:** ![dchavan](https://avatars.discourse-cdn.com/v4/letter/d/a88e57/32.png) [@dchavan](https://discuss.elastic.co/u/dchavan)\
**Post date:** [October 13, 2022, 8:02pm UTC](https://discuss.elastic.co/t/inconsistent-timestamp-format-from-logstash-out/316568/3 "2022-10-13T20:02:32Z")

</div>

I don't have any specific configuration for @timestamp in the logstash config file. It's probably set to default. I am using logstash V8.3

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 13, 2022, 8:13pm UTC](https://discuss.elastic.co/t/inconsistent-timestamp-format-from-logstash-out/316568/4 "2022-10-13T20:13:59Z")

</div>

```auto
"@timestamp":"2022-10-12T15:51:23Z"
"@timestamp":"2022-10-12T15:51:23.000015Z"
"@timestamp":"2022-10-12T15:51:23.000029Z"

```

These are LS time when messages were received in nanoseconds. The value :23Z means :23.000000Z" Nanosec are [since ELK 8.x](https://github.com/elastic/logstash/issues/10822#issuecomment-954149331) If you want to change, use the date plugin

---

<div class="post-metadata">

**Author:** ![dchavan](https://avatars.discourse-cdn.com/v4/letter/d/a88e57/32.png) [@dchavan](https://discuss.elastic.co/u/dchavan)\
**Post date:** [October 13, 2022, 8:18pm UTC](https://discuss.elastic.co/t/inconsistent-timestamp-format-from-logstash-out/316568/5 "2022-10-13T20:18:39Z")

</div>

I do want the LS time to stay in nanoseconds, but I want to replace the one that gets truncated back to ":23.000000Z"

Would date plugin allow me to do that?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 13, 2022, 8:29pm UTC](https://discuss.elastic.co/t/inconsistent-timestamp-format-from-logstash-out/316568/6 "2022-10-13T20:29:51Z")

</div>

Not sure is it possible. Test

```auto
date
{
  match => ["@timestamp", "ISO8601"]
  target => "@timestamp"
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 10, 2022, 8:30pm UTC](https://discuss.elastic.co/t/inconsistent-timestamp-format-from-logstash-out/316568/7 "2022-11-10T20:30:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
