# Logs with time difference only in seconds not ordered properly

**URL:** <https://discuss.elastic.co/t/logs-with-time-difference-only-in-seconds-not-ordered-properly/228734>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 19, 2020, 1:58pm UTC](https://discuss.elastic.co/t/logs-with-time-difference-only-in-seconds-not-ordered-properly/228734 "2020-04-19T13:58:54Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![haneefh](https://avatars.discourse-cdn.com/v4/letter/h/439d5e/32.png) [@haneefh](https://discuss.elastic.co/u/haneefh)\
**Post date:** [April 19, 2020, 1:58pm UTC](https://discuss.elastic.co/t/logs-with-time-difference-only-in-seconds-not-ordered-properly/228734/1 "2020-04-19T13:58:54Z")

</div>

I am using filebeats to send logs. When log events with time differnce only in seconds do not appear properly in kibana. Below is my filbeat configuration. The latest logs appear first as of now in kibana, but for logs with time difference only in seconds dont appear right

- type: log  
enabled: true  
paths:
  - /opt/atlassian/jira/logs/catalina.out  
fields:  
log\_type: catalina  
log\_application: atlassian\_jira  
multiline.pattern: '^[0-9]{2}-[[:alpha:]]{3}-[0-9]{4}'  
multiline.negate: true  
multiline.match: after

18-Apr-2020 21:01:50.455 WARNING [http-nio-8080-exec-97] com.sun.jersey.spi.container.servlet.WebComponent.filterFor  
18-Apr-2020 21:01:55.891 WARNING [http-nio-8080-exec-149] com.sun.jersey.spi.container

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 20, 2020, 8:29pm UTC](https://discuss.elastic.co/t/logs-with-time-difference-only-in-seconds-not-ordered-properly/228734/2 "2020-04-20T20:29:55Z")

</div>

Could you run the following Elasticsearch query to see what timestamps are being captured in the documents indexed by Filebeat?

```auto
GET filebeat-*/_search?sort=@timestamp:asc&filter_path=hits.hits._source.@timestamp

```

Shaunak

---

<div class="post-metadata">

**Author:** ![haneefh](https://avatars.discourse-cdn.com/v4/letter/h/439d5e/32.png) [@haneefh](https://discuss.elastic.co/u/haneefh)\
**Post date:** [April 21, 2020, 6:18am UTC](https://discuss.elastic.co/t/logs-with-time-difference-only-in-seconds-not-ordered-properly/228734/3 "2020-04-21T06:18:58Z")

</div>

{"hits":{"hits":[{"\_source":{"@timestamp":"2020-04-11T16:07:40.000Z"}},{"\_source":{"@timestamp":"2020-04-11T16:07:40.000Z"}},{"\_source":{"@timestamp":"2020-04-11T16:07:40.0 00Z"}},{"\_source":{"@timestamp":"2020-04-11T16:07:40.000Z"}},{"\_source":{"@timestamp":"2020-04-11T16:07:40.000Z"}},{"_source":{"@timestamp":"2020-04-11T16:07:40.000Z"}},{"_ source":{"@timestamp":"2020-04-11T16:07:40.000Z"}},{"\_source":{"@timestamp":"2020-04-11T16:07:40.000Z"}},{"\_source":{"@timestamp":"2020-04-11T16:07:40.000Z"}},{"\_source":{" @timestamp":"2020-04-11T16:07:40.000Z"}}]}}

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 21, 2020, 9:21am UTC](https://discuss.elastic.co/t/logs-with-time-difference-only-in-seconds-not-ordered-properly/228734/4 "2020-04-21T09:21:01Z")

</div>

Thanks, that tells us that the `@timestamp` values are being indexed at second precision. Which indicates that there's some issue with parsing between Filebeat and Elasticsearch, i.e. the Kibana side of things is working fine.

Next, could you post your **complete** `filebeat.yml` please (with any sensitive information redacted)?

Thanks,

Shaunak

---

<div class="post-metadata">

**Author:** ![haneefh](https://avatars.discourse-cdn.com/v4/letter/h/439d5e/32.png) [@haneefh](https://discuss.elastic.co/u/haneefh)\
**Post date:** [April 21, 2020, 10:31am UTC](https://discuss.elastic.co/t/logs-with-time-difference-only-in-seconds-not-ordered-properly/228734/5 "2020-04-21T10:31:04Z")

</div>

Hi shaun,  
I am pasting the filebeat configuration below. Also we use logstash before elastic search to parse the log time instead of event creation time. I am pasting the logstash configuration as well.

Filebeat configuration

- type: log  
enabled: true  
paths:
  - /opt/atlassian/confluence/logs/catalina.out  
fields:  
log\_type: catalina  
log\_application: atlassian\_confluence  
multiline.pattern: '^[0-9]{2}-[[:alpha:]]{3}-[0-9]{4}'  
multiline.negate: true  
multiline.match: after

Logstash Configuration

filter {  
if [fields][log\_type] == "catalina" {  
grok {  
match =\> { "message" =\> "(?%{MONTHDAY}-%{MONTH}-%{YEAR} %{HOUR}:?%{MINUTE}(?::?%{SECOND}))\s%{LOGLEVEL:level}\s+[%{DATA:thread}]\s+%{GREEDYDATA:log}" }  
}  
date {  
match =\> ["logtimestamp2", "dd-MMM-yyyy HH:mm:ss.SSS"]  
target =\> "datestamp2"  
}  
}

else if [fields][log\_type] == "Atlassian" {

grok {  
match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:logtimestamp3}\s+%{GREEDYDATA:thread}\s+%{LOGLEVEL:level}\s+%{GREEDYDATA:message}" }  
}  
date {  
match =\> ["logtimestamp3", "ISO8601"]  
target =\> "datestamp3"  
}  
}  
else if [fields][log\_type] == "Atlassian\_confluence" {

grok {  
match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:logtimestamp3}\s+%{LOGLEVEL:level}\s+%{GREEDYDATA:message}" }  
}  
date {  
match =\> ["logtimestamp3", "ISO8601"]  
target =\> "datestamp3"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![haneefh](https://avatars.discourse-cdn.com/v4/letter/h/439d5e/32.png) [@haneefh](https://discuss.elastic.co/u/haneefh)\
**Post date:** [May 13, 2020, 7:11am UTC](https://discuss.elastic.co/t/logs-with-time-difference-only-in-seconds-not-ordered-properly/228734/6 "2020-05-13T07:11:34Z")

</div>

Hi @shaunak,  
Did you get a chance to review this

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 10, 2020, 7:11am UTC](https://discuss.elastic.co/t/logs-with-time-difference-only-in-seconds-not-ordered-properly/228734/7 "2020-06-10T07:11:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
