# Logstash Custom Timestamp issue

**URL:** <https://discuss.elastic.co/t/logstash-custom-timestamp-issue/174678>\
**Category:** Logstash\
**Created:** [March 31, 2019, 1:25pm UTC](https://discuss.elastic.co/t/logstash-custom-timestamp-issue/174678 "2019-03-31T13:25:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![lakshykar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lakshykar/32/43198_2.png) [@lakshykar](https://discuss.elastic.co/u/lakshykar)\
**Post date:** [March 31, 2019, 1:25pm UTC](https://discuss.elastic.co/t/logstash-custom-timestamp-issue/174678/1 "2019-03-31T13:25:57Z")

</div>

Hi,

`I am trying to put transaction data into elasticsearch, i want to override @timestamp with actual transaction time, but after converting timestamp , getting different time.`

below if my conf file:

```
input {
  file{
	path => "/home/optimus/kibana/data/TX_DUMP_PPBL2019-03-31_16:41:431554030703.csv"
	start_position =>"beginning"
	sincedb_path => "/dev/null"
  }
}

filter{
  csv{
  separator => ","
  skip_header => true
  columns => ["Tid", "TxTime", "Amount", "BankName", "IFSC","Account" ,"Sender Name","Sender Cell","RRN","BankTid","Status","Status Desc","ResCode","ResDesc","Pipe","Recon","ReqAt","ResAt","ResTime"]

  }

  mutate {
	convert => {
		"Amount" => "float"
		"Status" => "integer"
		"Pipe" => "integer"
		"Recon" => "integer"
		"TxTime" => "string"
  }
}

  date {
	  match => ["TxTime" , "ISO8601" , "yyyy-MM-dd HH:mm:ss"]
	  target => "@timestamp"
	  remove_field => ["TxTime", "timestamp remove"]
  }

  mutate{
	add_field => {
	"Tag" => "Test"
	}

	remove_field => ["host", "@version","path"]
	rename => {

	}

  }
}

output{
  stdout{
  codec => rubydebug
  }
}

Sample input: 
1300112054,2019-03-25 13:47:23,5000,SBI,SBIN0000001,63026818178,Rohit,8851929333,NA,1000007219,0,Fail,1105,Corporate First leg of transactions failed or pending,9,0,2019-03-25 13:47:23,2019-03-25 13:47:24,1

Output:
{
	"Status Desc" => "Fail",
		  "Recon" => 0,
		"BankTid" => "1000007219",
	 "@timestamp" => **2019-03-25T08:17:23.000Z** ,
			"Tid" => "1300112054",
		"ResTime" => "1",
		 "Amount" => 5000.0,
	"Sender Name" => "Rohit",
	   "BankName" => "SBI",
		  "ReqAt" => "2019-03-25 13:47:23",
			"Tag" => "Test",
	"Sender Cell" => "8851929333",
		"ResDesc" => "Corporate First leg of transactions failed or pending",
		"Account" => "63026818178",
		"ResCode" => "1105",
			"RRN" => "NA",
		"message" => "1300112054, **2019-03-25 13:47:23** ,5000,SBI,SBIN0000001,63026818178,Rohit,8851929333,NA,1000007219,0,Fail,1105,Corporate First leg of transactions failed or pending,9,0,2019-03-25 13:47:23,2019-03-25 13:47:24,1",
		  "ResAt" => "2019-03-25 13:47:24",
		   "IFSC" => "SBIN0000001",
		 "Status" => 0,
		   "Pipe" => 9
}

```

Can someone please help why there is a different of around 5 hrs, and how i can correct this?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 31, 2019, 10:51pm UTC](https://discuss.elastic.co/t/logstash-custom-timestamp-issue/174678/2 "2019-03-31T22:51:38Z")

</div>

> [@lakshykar](#):
>
> Can someone please help why there is a different of around 5 hrs, and how i can correct this?

logstash is assuming that the timestamp in the log is in your local timezone and it is converting it to UTC. It is doing that by subtracting 5:30, which suggests you are in the Asia/Kolkota timezone.

The Elastic stack always stores times as UTC. The timestamp in the logfile is in some other timezone, then pass the [timezone](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html#plugins-filters-date-timezone) option to the date filter. If the timestamp in the log file is in Asia/Kolkota then you do not need to change anything -- it is working correctly.

---

<div class="post-metadata">

**Author:** ![lakshykar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lakshykar/32/43198_2.png) [@lakshykar](https://discuss.elastic.co/u/lakshykar)\
**Post date:** [April 1, 2019, 7:48am UTC](https://discuss.elastic.co/t/logstash-custom-timestamp-issue/174678/3 "2019-04-01T07:48:42Z")

</div>

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 29, 2019, 7:48am UTC](https://discuss.elastic.co/t/logstash-custom-timestamp-issue/174678/4 "2019-04-29T07:48:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
