# Logstash date filter not replacing @timestamp field

**URL:** <https://discuss.elastic.co/t/logstash-date-filter-not-replacing-timestamp-field/75549>\
**Category:** Logstash\
**Created:** [February 17, 2017, 6:04pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-replacing-timestamp-field/75549 "2017-02-17T18:04:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shirel\_Vaiman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shirel_vaiman/32/15638_2.png) [@Shirel\_Vaiman](https://discuss.elastic.co/u/Shirel_Vaiman)\
**Post date:** [February 17, 2017, 6:04pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-replacing-timestamp-field/75549/1 "2017-02-17T18:04:38Z")

</div>

Hi all,  
Please assist, as I'm already becoming desperate.  
I'm unable to replace the @timestamp field with the actual log time.  
I've tried all kinds of help from the internet but no luck.  
This is my logstash filter date config:  
date {  
match =\> ["logtime", "ISO8601"]  
timezone =\> "UTC"  
target =\> "@timestamp"  
add\_tag =\> ["timestamp\_match"]  
}  
This is an example of grok filter:  
grok {  
match =\> [  
"message", "%{TIMESTAMP\_ISO8601:logtime} [PID %{NUMBER:pid}]\t[%{WORD:levelname}]\t[%{GREEDYDATA:content}"  
]  
}

This is the debug:  
[2017-02-17T18:00:29,327][DEBUG][logstash.pipeline] output received {"event"=\>{"offset"=\>4760815, "input\_type"=\>"log", "pid"=\>"17206", "source"=\>"/etc/qa/log/qamt1-all.log", "message"=\>"2017-02-17 18:00:21,341 [PID 17206]\t[INFO]\t[test]\[tmiddleware.py:11](http://tmiddleware.py:11)\ttenant.middleware: handling request for tenant test", "type"=\>"django", "content"=\>"handling request for tenant test", "tags"=\>["beats\_input\_codec\_plain\_applied", "qa\_server", "dashboards"], "@timestamp"=\>2017-02-17T18:00:24.311Z, "filename"=\>"[middleware.py](http://middleware.py)", "lineno"=\>"11", "@version"=\>"1", "beat"=\>{"hostname"=\>"[test.net](http://test.net)", "name"=\>"[test.net](http://test.net)", "version"=\>"5.1.2"}, "host"=\>"[test.net](http://test.net)", "name"=\>"tenant.middleware", "levelname"=\>"INFO", "logtime"=\>"2017-02-17 18:00:21,341", "tenant"=\>"test"}}

in the kibana I see both @timestamp and logtime fields, which are not identical. Differences are in milliseconds, but it is very hard to read with millions of logs per minute.

I appreciate all the help I can get!!  
Thank you!

---

<div class="post-metadata">

**Author:** ![krishna\_chaitanya](https://avatars.discourse-cdn.com/v4/letter/k/b5a626/32.png) [@krishna\_chaitanya](https://discuss.elastic.co/u/krishna_chaitanya)\
**Post date:** [February 17, 2017, 6:41pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-replacing-timestamp-field/75549/2 "2017-02-17T18:41:16Z")

</div>

Try escaping the characters in grok pattern. Change  
**`[`** TO **`\[`**  
**`\t`** TO **`\\t`**

Try this for debugging. [http://grokdebug.herokuapp.com/](http://grokdebug.herokuapp.com/)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 20, 2017, 6:50am UTC](https://discuss.elastic.co/t/logstash-date-filter-not-replacing-timestamp-field/75549/3 "2017-02-20T06:50:08Z")

</div>

Since filters are processed in order the date filter that parses the `logtime` field needs to come after the grok filter that creates the `logtime` field.

---

<div class="post-metadata">

**Author:** ![Shirel\_Vaiman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shirel_vaiman/32/15638_2.png) [@Shirel\_Vaiman](https://discuss.elastic.co/u/Shirel_Vaiman)\
**Post date:** [March 4, 2017, 9:26pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-replacing-timestamp-field/75549/4 "2017-03-04T21:26:39Z")

</div>

Thanks Magnus,  
That was the problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 1, 2017, 9:26pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-replacing-timestamp-field/75549/5 "2017-04-01T21:26:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
