# Is there a way to map a date to milliseconds since epoch for Logstash?

**URL:** <https://discuss.elastic.co/t/is-there-a-way-to-map-a-date-to-milliseconds-since-epoch-for-logstash/67798>\
**Category:** Logstash\
**Created:** [December 1, 2016, 5:46pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-map-a-date-to-milliseconds-since-epoch-for-logstash/67798 "2016-12-01T17:46:16Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![EuclideanSearch](https://avatars.discourse-cdn.com/v4/letter/e/c77e96/32.png) [@EuclideanSearch](https://discuss.elastic.co/u/EuclideanSearch)\
**Post date:** [December 1, 2016, 5:46pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-map-a-date-to-milliseconds-since-epoch-for-logstash/67798/1 "2016-12-01T17:46:16Z")

</div>

Hi,

I have a date field (timestmap) (ES type is date) in my current Elasticsearch cluster and, among other things, I want to use Logstash to create a field consisting of the milliseconds since epoch for the timestamp. Now, [https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html) shows that there are plenty of ways to go from milliseconds since epoch to a date, but is there a way to go the other way (from date to milliseconds since epoch)?

Cheers,  
EuclideanSearch

---

<div class="post-metadata">

**Author:** ![hartfordfive](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hartfordfive/32/44794_2.png) [@hartfordfive](https://discuss.elastic.co/u/hartfordfive)\
**Post date:** [December 1, 2016, 6:13pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-map-a-date-to-milliseconds-since-epoch-for-logstash/67798/2 "2016-12-01T18:13:09Z")

</div>

You could use the ruby filter to do something like this.

---

<div class="post-metadata">

**Author:** ![EuclideanSearch](https://avatars.discourse-cdn.com/v4/letter/e/c77e96/32.png) [@EuclideanSearch](https://discuss.elastic.co/u/EuclideanSearch)\
**Post date:** [December 2, 2016, 5:16pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-map-a-date-to-milliseconds-since-epoch-for-logstash/67798/3 "2016-12-02T17:16:29Z")

</div>

> [@hartfordfive](#):
>
> You could use the ruby filter to do something like this.

Thank you hartfordfive. Similarly, is there a 'out of the box' way to get a ISO8601 String from a date field or will a ruby script be required for that as well'?

---

<div class="post-metadata">

**Author:** ![hartfordfive](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hartfordfive/32/44794_2.png) [@hartfordfive](https://discuss.elastic.co/u/hartfordfive)\
**Post date:** [December 2, 2016, 6:22pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-map-a-date-to-milliseconds-since-epoch-for-logstash/67798/4 "2016-12-02T18:22:01Z")

</div>

When you say going from a date field to an ISO8601 date string, what exactly is the format of your date field? Is it still the millisecond timestamp? Could you please include some examples in here just to clarify things?

---

<div class="post-metadata">

**Author:** ![EuclideanSearch](https://avatars.discourse-cdn.com/v4/letter/e/c77e96/32.png) [@EuclideanSearch](https://discuss.elastic.co/u/EuclideanSearch)\
**Post date:** [December 2, 2016, 6:26pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-map-a-date-to-milliseconds-since-epoch-for-logstash/67798/5 "2016-12-02T18:26:52Z")

</div>

My date field is stored as a Date type (Date mapping) in Elasticsearch. For example, a document is:  
{  
"uuid": "6ea7bb7d-95c5-4e4d-9649-8a80021049a2", \<- String Mapping in ES  
"timestamp": "2016-11-29T20:08:00.775Z", \<- has a Date mapping in ES  
... other fields ...  
}

---

<div class="post-metadata">

**Author:** ![hartfordfive](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hartfordfive/32/44794_2.png) [@hartfordfive](https://discuss.elastic.co/u/hartfordfive)\
**Post date:** [December 2, 2016, 8:25pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-map-a-date-to-milliseconds-since-epoch-for-logstash/67798/6 "2016-12-02T20:25:47Z")

</div>

Well if you're simply using something like Kibana to query the data, you'll already see an ISO8601 compliant UTC date/time in the "@timestamp" field. I guess I just don't understand your use case on why you'd need to do this extra conversion in logstash on each event if you already have a valid date field in it?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 30, 2016, 8:26pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-map-a-date-to-milliseconds-since-epoch-for-logstash/67798/7 "2016-12-30T20:26:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
