# Logstash adding date at the beginning of the each record

**URL:** <https://discuss.elastic.co/t/logstash-adding-date-at-the-beginning-of-the-each-record/203936>\
**Category:** Logstash\
**Created:** [October 16, 2019, 9:54pm UTC](https://discuss.elastic.co/t/logstash-adding-date-at-the-beginning-of-the-each-record/203936 "2019-10-16T21:54:55Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sekharvijju](https://avatars.discourse-cdn.com/v4/letter/s/ecae2f/32.png) [@sekharvijju](https://discuss.elastic.co/u/sekharvijju)\
**Post date:** [October 16, 2019, 9:54pm UTC](https://discuss.elastic.co/t/logstash-adding-date-at-the-beginning-of-the-each-record/203936/1 "2019-10-16T21:54:55Z")

</div>

Hi Logstash gurus,

I m trying to setup a basic logstash client to push server logs into S3 bucket using Input plugin & s3 output plugin.

input {  
file {  
path =\> "/logs/sys\*"  
exclude =\> "\*.tar"  
start\_position =\> "beginning"  
sincedb\_path =\> "/var/logstash/.sincedb9"  
sincedb\_clean\_after =\> "4"  
}  
}  
output {  
s3{  
access\_key\_id =\> "XXXXXXXXXXXXXXXXXXXX"  
secret\_access\_key =\> "XXXXXXXXXXXX"  
region =\> "xx-xxxx-1"  
bucket =\> "xyz  
size\_file =\> 10480000  
time\_file =\> 5 #5 minutes  
codec =\> "line"  
canned\_acl =\> "private"  
prefix =\> "logs"  
}  
}

At the beginning of each log event (row/line), it's adding the timestamp in UTC and then the actual event itself from the logfile as below:

**2019-10-16T21:26:14.530Z** XXXX XXXX XXXXXXXXXXXX XXXXXXXXXXX "GET XXXXXXX HTTP/1.1" 200 2057

Went through logstash documentation for input plugin and S3 output plugin and did not find anything talking about the timestamp being added automatically. time\_file was added to rollup the events at every 5 minutes interval.

How do I get rid of that default timestamp? Any ideas or help is appreciated.

Regards,

Vijay

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 17, 2019, 3:44pm UTC](https://discuss.elastic.co/t/logstash-adding-date-at-the-beginning-of-the-each-record/203936/2 "2019-10-17T15:44:32Z")

</div>

The default message format for the line codec is to add the timestamp and hostname at the beginning of the line. Specify the format option if you do not want that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 14, 2019, 3:44pm UTC](https://discuss.elastic.co/t/logstash-adding-date-at-the-beginning-of-the-each-record/203936/3 "2019-11-14T15:44:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
