# Logstash adds timestamp value to the output logs automatically

**URL:** <https://discuss.elastic.co/t/logstash-adds-timestamp-value-to-the-output-logs-automatically/176251>\
**Category:** Logstash\
**Created:** [April 10, 2019, 3:10pm UTC](https://discuss.elastic.co/t/logstash-adds-timestamp-value-to-the-output-logs-automatically/176251 "2019-04-10T15:10:16Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![naveenrt23](https://avatars.discourse-cdn.com/v4/letter/n/47e85d/32.png) [@naveenrt23](https://discuss.elastic.co/u/naveenrt23)\
**Post date:** [April 10, 2019, 3:10pm UTC](https://discuss.elastic.co/t/logstash-adds-timestamp-value-to-the-output-logs-automatically/176251/1 "2019-04-10T15:10:17Z")

</div>

Hello,

I am trying to use influxdb output plugin v-5.0.5 with logstash v-6.2.3.  
I am getting parsing exceptions but on further looking,i see "logstash and a timestamp value" is getting added to all the output logs. When the output is seen in rubydebug format i dont see the timestamp value and logstash. Does anyone know how to get rid of these ?

> ` [2019-04-09T15:09:33,095][WARN][logstash.outputs.influxdb] Non recoverable exception while writing to InfluxDB  
> {:exception=\>#\<InfluxDB::Error: {"error":"unable to parse 'logstash,host=localhost username="admin",  
> site="test",timestamp\_local="20190409120930",resource\_type="/users/admin",timestamp=1554811770000i,  
> @timestamp=2019-04-09T19:09:32.368Z,repo="api",resource\_path="/users/admin",  
> message="20190409120930|14|REQUEST|_ **.**.__._**|admin|GET|/users/admin|HTTP/1.1|200|0",  
> duration="14",clientip="**_. __.__._\*\*",@version="1",statuscode="200",bytes="0",  
> timestamp\_object=2019-04-09T12:09:30.000Z,type="request",env="stage",requesttype="REQUEST",  
> resource="/users/admin",resource\_name="admin",method="GET",protocol="HTTP/1.1" 1554836972368': invalid number"}
> 
> > }  
> > {  
> > "username" =\> "admin",  
> > "site" =\> "test",  
> > "timestamp\_local" =\> "20190409120930",  
> > "resource\_type" =\> "/users/admin",  
> > "host" =\> "localhost",  
> > "timestamp" =\> 1554811770000,  
> > "@timestamp" =\> 2019-04-09T19:09:32.368Z,  
> > "repo" =\> "api",  
> > "resource\_path" =\> "/users/admin",  
> > "message" =\> "20190409120930|14|REQUEST|_ **.**.__._**|admin|GET|/users/admin|HTTP/1.1|200|0",  
> > "duration" =\> "14",  
> > "clientip" =\> "**_. __.__._\*\*",  
> > "@version" =\> "1",  
> > "statuscode" =\> "200",  
> > "bytes" =\> "0",  
> > "timestamp\_object" =\> 2019-04-09T12:09:30.000Z,  
> > "type" =\> "request",  
> > "env" =\> "stage",  
> > "requesttype" =\> "REQUEST",  
> > "resource" =\> "/users/admin",  
> > "resource\_name" =\> "admin",  
> > "method" =\> "GET",  
> > "protocol" =\> "HTTP/1.1"  
> > }`

My config:

> input {  
> kafka {  
> id =\> "kafka1"  
> group\_id =\> "logstash"  
> bootstrap\_servers =\> ["localhost:9092"]  
> topics =\> ["request.log"]  
> consumer\_threads =\> 2  
> type =\> "request"  
> }  
> }  
> ###################################  
> filter {  
> if [type] == "request" {  
> if "/api/test" in [message] { drop{ } }  
> else {  
> grok {  
> # Enable multiple matchers  
> break\_on\_match =\> false  
> match =\> { "message" =\> "%{DATA:timestamp\_local}|%{NUMBER:duration}|%{WORD:requesttype}|%{IP:clientip}|%{DATA:username}|%{WORD:method}|%{DATA:resource}|%{DATA:protocol}|%{NUMBER:statuscode}|%{NUMBER:bytes}" }  
> # Extract repo and path  
> match =\> { "resource" =\> "/%{DATA:repo}/%{GREEDYDATA:resource\_path}"}  
> # Extract resource name  
> match =\> { "resource\_path" =\> "(?\<resource\_name\>[^/]+$)" }  
> # Extract file extension  
> match =\> { "resource\_path" =\> "(?\<resource\_type\>[^.]+$)" }  
> }  
> }  
> #Parse date field  
> date {  
> timezone =\> "UTC"  
> match =\> ["timestamp\_local" , "yyyyMMddHHmmss"]  
> target =\> "timestamp\_object"  
> } }  
> ruby {  
> code =\> "event.set('timestamp', event.get('timestamp\_object').to\_i \* 1000)"  
> }  
> }  
> #############################  
> output {  
> if [type] == "request" {  
> influxdb {  
> codec =\> json  
> host =\> "_..._"  
> db =\> "logstash\_test"  
> port =\> 8086  
> use\_event\_fields\_for\_data\_points =\> true  
> exclude\_fields =\> ["logstash"]  
> }  
> stdout { codec =\> rubydebug }  
> }  
> }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2019, 3:10pm UTC](https://discuss.elastic.co/t/logstash-adds-timestamp-value-to-the-output-logs-automatically/176251/2 "2019-05-08T15:10:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
