# Is @timestamp in kibana from filebeat or logstash?

**URL:** <https://discuss.elastic.co/t/is-timestamp-in-kibana-from-filebeat-or-logstash/326836>\
**Category:** Kibana\
**Created:** [March 2, 2023, 10:02am UTC](https://discuss.elastic.co/t/is-timestamp-in-kibana-from-filebeat-or-logstash/326836 "2023-03-02T10:02:03Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![LongKang\_Fan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/longkang_fan/32/97516_2.png) [@LongKang\_Fan](https://discuss.elastic.co/u/LongKang_Fan)\
**Post date:** [March 2, 2023, 10:02am UTC](https://discuss.elastic.co/t/is-timestamp-in-kibana-from-filebeat-or-logstash/326836/1 "2023-03-02T10:02:03Z")

</div>

So the thing is I have filebeat that ship the log file to logstash then to the elasticsearch cluster. And I created the data view the get the messages on the discover page. I wonder where this @timestamp field comes from? Is the time elasticsearch received the message? or the time logstash received the message? or filebeat scanned the message?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/e/dea9fdea56b6ed334cb6c0e66b966b9e5c89ae6a.png)

Thanks

---

<div class="post-metadata">

**Author:** ![eMitch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emitch/32/93607_2.png) [@eMitch](https://discuss.elastic.co/u/eMitch)\
**Post date:** [March 2, 2023, 5:43pm UTC](https://discuss.elastic.co/t/is-timestamp-in-kibana-from-filebeat-or-logstash/326836/2 "2023-03-02T17:43:09Z")

</div>

Hey @LongKang_Fan - Take a look at [this answer](https://discuss.elastic.co/t/when-does-timestamp-get-added/129844/2). I believe it's still relevant.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 2, 2023, 8:36pm UTC](https://discuss.elastic.co/t/is-timestamp-in-kibana-from-filebeat-or-logstash/326836/3 "2023-03-02T20:36:11Z")

</div>

In your case assuming you are just using logstash as a passthrough the timestamp comes from filebeat per the description above.

If you want to use the timestamp that is within your message field you can do that with some processing.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 2, 2023, 10:27pm UTC](https://discuss.elastic.co/t/is-timestamp-in-kibana-from-filebeat-or-logstash/326836/4 "2023-03-02T22:27:15Z")

</div>

@timestamp is from LS, they explained how is generated.

I assume you are confused why you have time difference. If you like to update @timestamp to correct value-from a log, you have to parse the message, extract date from the begging, 2nd field is IP of something, etc.  
So, you need grok or dissect to split the message in the fields.  
After that convert 1. field to date format and overwrite @timestamp. This is how you will have @timestamp from the log file.

```auto
    date {
      match => ["timestamp", "MMM d HH:mm:ss.SSS", "MMM dd HH:mm:ss.SSS"]
      timezone => "Asia/Dubai" # optionally
      target=> "@timestamp" # this is default
    }

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 2, 2023, 11:46pm UTC](https://discuss.elastic.co/t/is-timestamp-in-kibana-from-filebeat-or-logstash/326836/5 "2023-03-02T23:46:45Z")

</div>

> [@Rios](#):
>
> @timestamp is from LS, they explained how is generated.

Hi @rios, Actually if he is using Filebeat -\> Logstash -\> Elasticsearch the `@timestamp` is from Filebeat

But I agree ... the user probably wants to use the timestamp from withing the message as you showed, then the `@timestamp` will most accurately match the data in the log.

---

<div class="post-metadata">

**Author:** ![LongKang\_Fan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/longkang_fan/32/97516_2.png) [@LongKang\_Fan](https://discuss.elastic.co/u/LongKang_Fan)\
**Post date:** [March 3, 2023, 2:22am UTC](https://discuss.elastic.co/t/is-timestamp-in-kibana-from-filebeat-or-logstash/326836/6 "2023-03-03T02:22:45Z")

</div>

Hi @stephenb

The reason I am doing this is I want to find a way to show the logs in the Kibana in order. So I am thinking it could help if the `@timestamp` comes from Filebeat since Filebeat reads the file line by line.

I wonder if the `@timestamp` comes from Filebeat, then the message shown on the Kibana should be ordered if I sort by `@timestamp`

So I have created a file named `b.log` and this is its content:

> 2023-03-03 10:06:19,855 192.168.0.1 fbloggs Protocol problem: connection reset 0  
> 2023-03-03 10:06:19,856 192.168.0.1 fbloggs Protocol problem: connection reset 1  
> .......  
> .......  
> .......  
> 2023-03-03 10:06:19,892 192.168.0.1 fbloggs Protocol problem: connection reset 196  
> 2023-03-03 10:06:19,892 192.168.0.1 fbloggs Protocol problem: connection reset 197  
> 2023-03-03 10:06:19,892 192.168.0.1 fbloggs Protocol problem: connection reset 198  
> 2023-03-03 10:06:19,892 192.168.0.1 fbloggs Protocol problem: connection reset 199

And I use Filebeat -\> Logstash -\> Elasticsearch then gets the output but unordered.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/1/514daecc3fd118d61cf97ca54ebde31e5fc22cfc.png)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 3, 2023, 2:44am UTC](https://discuss.elastic.co/t/is-timestamp-in-kibana-from-filebeat-or-logstash/326836/7 "2023-03-03T02:44:57Z")

</div>

> [@LongKang\_Fan](#):
>
> And I use Filebeat -\> Logstash -\> Elasticsearch then gets the output but unordered.

Did you set the number of workers to `1` ? Logstash per default will process filters and outputs in parallel and [does not guarantee event order](https://www.elastic.co/guide/en/logstash/current/processing.html#event-ordering).

You need to set `pipeline.workers` to `1` in your `pipelines.yml` for the pipeline you want to keep the order.

But even doing this, I'm not sure that the order is guaranteed in Kibana since you may have events with the same `@timestamp` value and they may be shown out of order.

---

<div class="post-metadata">

**Author:** ![LongKang\_Fan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/longkang_fan/32/97516_2.png) [@LongKang\_Fan](https://discuss.elastic.co/u/LongKang_Fan)\
**Post date:** [March 3, 2023, 2:57am UTC](https://discuss.elastic.co/t/is-timestamp-in-kibana-from-filebeat-or-logstash/326836/8 "2023-03-03T02:57:03Z")

</div>

Hi @leandrojmp

I did not set the workers to 1. I remembered that it will affect the performance if set to 1?

> But even doing this, I'm not sure that the order is guaranteed in Kibana since you may have events with the same `@timestamp` value and they may be shown out of order.

I did not release the fact the messages will be out of order if the `@timestamp` values are the same! This is actually the reason and explains my previous post's issues. 👍 👍 👍

But how should I guarantee the order? Or, this is not recommended to do in Elasticsearch?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 3, 2023, 3:05am UTC](https://discuss.elastic.co/t/is-timestamp-in-kibana-from-filebeat-or-logstash/326836/9 "2023-03-03T03:05:42Z")

</div>

> [@LongKang\_Fan](#):
>
> I remembered that it will affect the performance if set to 1?

Yes, it could affect the performance, the processing will be done by 1 worker only and sequentially, not in parallel.

> [@LongKang\_Fan](#):
>
> But how should I guarantee the order? Or, this is not recommended to do in Elasticsearch?

It really depends on your data, you would need to be able to have another field to sort on, for example, you could parse your message and put the value after _connection reset_ on a field and sort using this field as well.

For elastic it makes no difference, it really depends on your data and what you want to do with it.

---

<div class="post-metadata">

**Author:** ![LongKang\_Fan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/longkang_fan/32/97516_2.png) [@LongKang\_Fan](https://discuss.elastic.co/u/LongKang_Fan)\
**Post date:** [March 3, 2023, 3:11am UTC](https://discuss.elastic.co/t/is-timestamp-in-kibana-from-filebeat-or-logstash/326836/10 "2023-03-03T03:11:22Z")

</div>

Hi @leandrojmp

Thanks! This really helps me a lot and makes me more clear！

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 31, 2023, 3:11am UTC](https://discuss.elastic.co/t/is-timestamp-in-kibana-from-filebeat-or-logstash/326836/11 "2023-03-31T03:11:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
