# Ingest Grok Pipeline - Unix Timestamps

**URL:** <https://discuss.elastic.co/t/ingest-grok-pipeline-unix-timestamps/106700>\
**Category:** Elasticsearch\
**Created:** [November 7, 2017, 2:24pm UTC](https://discuss.elastic.co/t/ingest-grok-pipeline-unix-timestamps/106700 "2017-11-07T14:24:40Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Speedman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/speedman/32/37066_2.png) [@Speedman](https://discuss.elastic.co/u/Speedman)\
**Post date:** [November 7, 2017, 2:24pm UTC](https://discuss.elastic.co/t/ingest-grok-pipeline-unix-timestamps/106700/1 "2017-11-07T14:24:40Z")

</div>

Hi all. I'm trying to figure out how to convert an epoch timestamp (in seconds.milliseconds format) into a date/time format in Elasticsearch. Here's an example of the log line I'm trying to parse:

`8 - {8249} [1508745765.02767] Execution Time: 0.671`

I've already set up the following grok processor on the ingest pipeline:

```
{
  "description": "Grok Transaction Times From HttpLog",
  "processors": [
    {
      "grok": {
        "field": "message",
        "patterns": ["\\A%{NUMBER:server_id} - \\{%{NUMBER:p_id}} \\[%{NUMBER:epoch_timestamp}] Execution Time: %{NUMBER:exec_time}"]
      }
    }
  ]
}

```

I found [this post](https://discuss.elastic.co/t/elastic-ingest-with-multiple-grok-processors/70451) that seems to describe a similar problem, but I'm having difficulty figuring out how to fit this to my own pattern. I have come to the conclusion that I need to multiply the value by 1000 to get a new value that I can then convert with the UNIX\_MS format, but how do I define that in the pipeline?

(Disclaimer: we are not using Logstash for various reasons that aren't open to discussion right now. It's an option for the future but only as a _last_ resort.)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 7, 2017, 3:14pm UTC](https://discuss.elastic.co/t/ingest-grok-pipeline-unix-timestamps/106700/2 "2017-11-07T15:14:44Z")

</div>

Does a date processor using UNIX (rather than UNIX\_MS) do the job for you?

---

<div class="post-metadata">

**Author:** ![Speedman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/speedman/32/37066_2.png) [@Speedman](https://discuss.elastic.co/u/Speedman)\
**Post date:** [November 7, 2017, 3:17pm UTC](https://discuss.elastic.co/t/ingest-grok-pipeline-unix-timestamps/106700/3 "2017-11-07T15:17:07Z")

</div>

Possibly. The only examples I've seen up to this point used UNIX\_MS, but now I see that UNIX is an option, and I'm presuming it means seconds since 1/1/70 instead of milliseconds.

---

<div class="post-metadata">

**Author:** ![Speedman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/speedman/32/37066_2.png) [@Speedman](https://discuss.elastic.co/u/Speedman)\
**Post date:** [November 7, 2017, 3:57pm UTC](https://discuss.elastic.co/t/ingest-grok-pipeline-unix-timestamps/106700/4 "2017-11-07T15:57:52Z")

</div>

I figured it out. Here's the solution:

```
{
  "description": "Grok Transaction Times From HttpLog",
  "processors": [
    {
      "grok": {
        "field": "message",
        "patterns": ["\\A%{NUMBER:server_id} - \\{%{NUMBER:p_id}} \\[%{NUMBER:trans_timestamp}] Execution Time: %{NUMBER:exec_time}"]
      }
    },
    {
      "date":{
        "field":"trans_timestamp",
        "formats":["UNIX"]
      }
    }
  ]
}

```

Just took me a little while to properly understand the order of operations with regard to adding additional processors.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 5, 2017, 3:58pm UTC](https://discuss.elastic.co/t/ingest-grok-pipeline-unix-timestamps/106700/5 "2017-12-05T15:58:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
