# Logfile Input - Timestamp fieled ismissing

**URL:** https://discuss.elastic.co/t/logfile-input-timestamp-fieled-ismissing/102736
**Category:** Logstash
**Created:** [October 4, 2017, 5:00pm UTC](https://discuss.elastic.co/t/logfile-input-timestamp-fieled-ismissing/102736 "2017-10-04T17:00:34Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![baldy2811](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/baldy2811/32/12744_2.png) [@baldy2811](https://discuss.elastic.co/u/baldy2811)
#### Post date: [October 4, 2017, 5:00pm UTC](https://discuss.elastic.co/t/logfile-input-timestamp-fieled-ismissing/102736/1 "2017-10-04T17:00:34Z")

</div>

Hi there,

i created some filter for nginx logs discribed at this website: [https://www.elastic.co/guide/en/logstash/current/logstash-config-for-filebeat-modules.html#parsing-nginx](https://www.elastic.co/guide/en/logstash/current/logstash-config-for-filebeat-modules.html#parsing-nginx)

Logstash shows me some error:

] An unexpected error occurred! {:error=\>#\<LogStash::Error: timestamp field is missing\>, :backtrace=\>["org/logstash/ext/JrubyEventExtLibrary.java:205:in `sprintf'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-7.4.0-java/lib/logstash/outputs/elasticsearch/common.rb:168:in`event\_action\_params'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-7.4.0-java/lib/logstash/outputs/elasticsearch/common.rb:44:in `event_action_tuple'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-7.4.0-java/lib/logstash/outputs/elasticsearch/common.rb:38:in`multi\_receive'", "org/jruby/RubyArray.java:2414:in `map'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-7.4.0-java/lib/logstash/outputs/elasticsearch/common.rb:38:in`multi\_receive'", "/usr/share/logstash/logstash-core/lib/logstash/output\_delegator\_strategies/shared.rb:13:in `multi_receive'", "/usr/share/logstash/logstash-core/lib/logstash/output_delegator.rb:49:in`multi\_receive'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:436:in `output_batch'", "org/jruby/RubyHash.java:1342:in`each'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:435:in `output_batch'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:381:in`worker\_loop'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:342:in `start\_workers'"]}

After a couple of time it starts running.

When i wanted to add some other logs without any filter i got the same error and logstash crashes.

Is there any default filter then i am able to read other logs not only nginx? Last time i used Logstash in version 3 or so.. sooo many thinks are different and it seems not adoptable.

Is there any easy way to read more logs then only nginx?

Cheers

Daniel

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 1, 2017, 5:00pm UTC](https://discuss.elastic.co/t/logfile-input-timestamp-fieled-ismissing/102736/2 "2017-11-01T17:00:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
