# Kibana overrides original time format from Elasticsearch

**URL:** <https://discuss.elastic.co/t/kibana-overrides-original-time-format-from-elasticsearch/281124>\
**Category:** Kibana\
**Created:** [August 11, 2021, 9:44pm UTC](https://discuss.elastic.co/t/kibana-overrides-original-time-format-from-elasticsearch/281124 "2021-08-11T21:44:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rtemotfuorco123](https://avatars.discourse-cdn.com/v4/letter/r/c89c15/32.png) [@rtemotfuorco123](https://discuss.elastic.co/u/rtemotfuorco123)\
**Post date:** [August 11, 2021, 9:44pm UTC](https://discuss.elastic.co/t/kibana-overrides-original-time-format-from-elasticsearch/281124/1 "2021-08-11T21:44:26Z")

</div>

Hi,

I have the index below and when I visualise it in Kibana, the `log_field.time` format is changed. I want to keep it as the original one which is RFC3339. How do I get this sorted? See image at the bottom please. By the way, I am using Fluent-bit to push the logs from K8S node.

Thanks

```auto
{
  "took" : 6,
  "timed_out" : false,
  "_shards" : {
    "total" : 1,
    "successful" : 1,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 1,
      "relation" : "eq"
    },
    "max_score" : 1.0,
    "hits" : [
      {
        "_index" : "dev-logs-8",
        "_type" : "json",
        "_id" : "yKoYN3sBEOe8G5qXyMFs",
        "_score" : 1.0,
        "_source" : {
          "@timestamp" : "2021-08-11T21:22:55.923Z",
          "log" : "{\"level\":\"error\",\"msg\":\"welcome to error page\",\"time\":\"2021-08-11T21:22:55Z\"}\n",
          "stream" : "stderr",
          "time" : "2021-08-11T21:22:55.923110495Z",
          "log_field" : {
            "level" : "error",
            "msg" : "welcome to error page",
            "time" : "2021-08-11T21:22:55Z"
          },
          "kubernetes" : {
            "pod_name" : "api-5b4b8fc569-msnjr",
            "namespace_name" : "dev",
            "pod_id" : "fb99f390-34aa-4e02-882f-42360019b4af",
            "labels" : {
              "app" : "api",
              "pod-template-hash" : "5b4b8fc569"
            },
            "host" : "minikube",
            "container_name" : "golang",
            "docker_id" : "87bfd17861c2e7fb4fffeb3ec8b9b6eb9540f4ac98db68430f6706ac5b74505f",
            "container_hash" : "me/efk@sha256:818f9c1fe6839e9ee47588446c3c7b0a11eecd7f9d029be1deb8b604a44bef96"
          }
        }
      }
    ]
  }
}

```

 ![a](https://us1.discourse-cdn.com/elastic/original/3X/8/e/8e7849cc6951890039e6001f490c48bbe9b3013b.png)

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [August 12, 2021, 5:29am UTC](https://discuss.elastic.co/t/kibana-overrides-original-time-format-from-elasticsearch/281124/2 "2021-08-12T05:29:10Z")

</div>

All fields that are indexed as the type `date` are actually stored internally as a long value representing _milliseconds since epoch_ (NOTE: you should be sending all `date` values in UTC).

What you are seeing is Kibana formatting the date value for display purposes. You can modify this format globally in Kibana's _Advanced Settings_...

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/4/143a1cbb6bae846217b2e33f01cd2c7f6a9edd18.png)

Alternatively you can specify the format on a per field basis in the Index Pattern for the Index...

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/a/2ab59019f8ee1b027a4bf733324de0a06f32014f.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 9, 2021, 5:29am UTC](https://discuss.elastic.co/t/kibana-overrides-original-time-format-from-elasticsearch/281124/3 "2021-09-09T05:29:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
