# Load Epoch time

**URL:** <https://discuss.elastic.co/t/load-epoch-time/44410>\
**Category:** Logstash\
**Created:** [March 15, 2016, 9:18am UTC](https://discuss.elastic.co/t/load-epoch-time/44410 "2016-03-15T09:18:35Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![chenbe2204](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@chenbe2204](https://discuss.elastic.co/u/chenbe2204)\
**Post date:** [March 15, 2016, 9:18am UTC](https://discuss.elastic.co/t/load-epoch-time/44410/1 "2016-03-15T09:18:35Z")

</div>

Hi ,

I'm trying to convert epoch time to human date.  
In my json file I tried to put the value of the field with "" and without "".  
I saw some answers about this in the web but in my case it doesn't work.  
The name of the field I want to change is **startTime**.  
This is my conf file:

input {  
file{  
path =\> ["/tmp\_31.json"]  
type =\> "json"  
start\_position =\> "beginning"  
sincedb\_path =\> "/dev/null"  
}  
}  
filter{  
grok {  
match =\> ['message', '(?"TestName":.\*"Agent":"[^"]+")' ]  
}  
date {  
match =\> ["startTime", "UNIX"]  
}  
json {  
source =\> "message"  
}  
}

output {  
stdout {  
codec =\> rubydebug  
}  
elasticsearch {  
host =\> "xx.xxx.xx.xx"  
protocol =\> "http"  
index =\> "index\_client"  
}  
}

BR,  
Chen

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 15, 2016, 9:31am UTC](https://discuss.elastic.co/t/load-epoch-time/44410/2 "2016-03-15T09:31:23Z")

</div>

> match =\> ['message', '(?"TestName":.\*"Agent":"[^"]+")' ]

Don't use a grok filter to parse JSON. Use the json codec or filter. Or what's the point of this filter? You're not extracting any fields from the source string so it seems pretty pointless.

> match =\> ["startTime", "UNIX"]

There is no `startTime` field when this filter runs. Try placing this filter after the json filter instead.

---

<div class="post-metadata">

**Author:** ![chenbe2204](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@chenbe2204](https://discuss.elastic.co/u/chenbe2204)\
**Post date:** [March 15, 2016, 10:07am UTC](https://discuss.elastic.co/t/load-epoch-time/44410/3 "2016-03-15T10:07:54Z")

</div>

I removed the grok filter , and add to the filter  
match =\> ["startTime", "UNIX"]  
This is the conf file filter after I changed it:  
filter{  
date {  
match =\> ["startTime", "UNIX"]  
}  
json {  
source =\> "message"  
}  
}

But it still doesn't convert the startTime.  
Is it matter if you put the value of the startTime as string or as number in the json file ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 15, 2016, 11:06am UTC](https://discuss.elastic.co/t/load-epoch-time/44410/4 "2016-03-15T11:06:56Z")

</div>

> But it still doesn't convert the startTime.

Logstash won't replace the `startTime` value. It'll populate the `@timestamp` field. If that's not what you want you need to set the `target` option for the date filter.

If you need further help you need to show us what the events look like, preferably by showing the output of a `stdout { codec => rubydebug }` output.

> Is it matter if you put the value of the startTime as string or as number in the json file ?

I'm pretty sure it doesn't matter.

---

<div class="post-metadata">

**Author:** ![chenbe2204](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@chenbe2204](https://discuss.elastic.co/u/chenbe2204)\
**Post date:** [March 15, 2016, 12:04pm UTC](https://discuss.elastic.co/t/load-epoch-time/44410/5 "2016-03-15T12:04:47Z")

</div>

This is my Json file:  
{"build\_name":"UT" ,"build\_number":80 ,"startTime":1458024571583 ,"result":"FAILURE" ,"duration":179725}

This is my conf file after I changed it:  
input {  
file{  
path =\> ["/tmp\_31.json"]  
type =\> "json"  
start\_position =\> "beginning"  
sincedb\_path =\> "/dev/null"  
}  
}

filter{  
date {  
match =\> ["startTime", "UNIX"]  
target =\> "@timestamp"  
}  
json {  
source =\> "message"  
}  
}

output {  
stdout {  
codec =\> rubydebug  
}  
elasticsearch {  
host =\> "xx.xxx.xx.xx"  
protocol =\> "http"  
index =\> "index\_client"  
}  
}

print screen after I load the json file:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/6/612de3870e00b2868a70567a1e569aaae9573d5e.png)

So I'm still doing something wrong ....

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 15, 2016, 12:07pm UTC](https://discuss.elastic.co/t/load-epoch-time/44410/6 "2016-03-15T12:07:55Z")

</div>

I repeat: Put the date filter after the json filter.

Where does the `Time` field come from? There's nothing in your configuration and the input JSON object that creates it.

---

<div class="post-metadata">

**Author:** ![chenbe2204](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@chenbe2204](https://discuss.elastic.co/u/chenbe2204)\
**Post date:** [March 16, 2016, 6:07am UTC](https://discuss.elastic.co/t/load-epoch-time/44410/7 "2016-03-16T06:07:30Z")

</div>

Hi ,

I also tried to put the time filter after the json filter (with and without target).  
I can see the new loaded index with the new record under the list of indexes in the ElasticSearch (using the command curl 'localhost:9200/\_cat/indices?v') but I can't reach the data in the Kibana

filter{  
json {  
source =\> "message"  
}  
}

filter{  
date {  
match =\> ["startTime", "UNIX"]  
target =\> "@timestamp"  
}  
}

The time is added automatically as the load time of the data into the ElasticSearch , I don't define in the conf file or in the Json file this field (It's also not part of the fields of the index\_client I create).  
I also tried the following things:

- to change the startTime in the Json file to string
- create 1 filter and put the data after the json  
It still doesn't work.

BR,  
Chen

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 16, 2016, 6:28am UTC](https://discuss.elastic.co/t/load-epoch-time/44410/8 "2016-03-16T06:28:45Z")

</div>

Your epoch is in milliseconds, so use UNIX\_MS instead of UNIX.

---

<div class="post-metadata">

**Author:** ![chenbe2204](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@chenbe2204](https://discuss.elastic.co/u/chenbe2204)\
**Post date:** [March 16, 2016, 7:14am UTC](https://discuss.elastic.co/t/load-epoch-time/44410/9 "2016-03-16T07:14:19Z")

</div>

Thanks for all your support !!!  
now it works 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:06am UTC](https://discuss.elastic.co/t/load-epoch-time/44410/10 "2017-07-06T05:06:48Z")

</div>


