# Logstash date filter truncating milliseconds when they are set to 000

**URL:** <https://discuss.elastic.co/t/logstash-date-filter-truncating-milliseconds-when-they-are-set-to-000/327770>\
**Category:** Logstash\
**Created:** [March 15, 2023, 4:22pm UTC](https://discuss.elastic.co/t/logstash-date-filter-truncating-milliseconds-when-they-are-set-to-000/327770 "2023-03-15T16:22:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Samuel\_Delepiere](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/samuel_delepiere/32/75345_2.png) [@Samuel\_Delepiere](https://discuss.elastic.co/u/Samuel_Delepiere)\
**Post date:** [March 15, 2023, 4:22pm UTC](https://discuss.elastic.co/t/logstash-date-filter-truncating-milliseconds-when-they-are-set-to-000/327770/1 "2023-03-15T16:22:21Z")

</div>

We use the following filter

```
date {
  match => ["timestampInUtc" , "UNIX_MS"]
  target => "timestamp"
  timezone => "UTC"
}

```

This works correctly except when the milliseconds are set to 000. In that case, they get truncated

For instance a timestamp of 1678895447001 will correctly get converted to 2023-03-15T15:50:47.001Z  
But a timestamp of 1678895447000 will get converted to 2023-03-15T15:50:47Z. The milliseconds are dropped

Using logstash 8.3.3

Would that be.a bug? Any workaround?

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 15, 2023, 5:47pm UTC](https://discuss.elastic.co/t/logstash-date-filter-truncating-milliseconds-when-they-are-set-to-000/327770/2 "2023-03-15T17:47:42Z")

</div>

> [@Samuel\_Delepiere](#):
>
> Would that be.a bug?

Yes. Fixed by [this](https://github.com/elastic/logstash/commit/5e372fed916ece63c68e26e0cb7e6a187c928960) commit.

It is unclear what you want from a workaround. The LogStash::Timestamp object has milliseconds (or nanoseconds) set to zero. The issue is when that is converted to a string. When are you doing the string conversion?

If it is being converted when sending to elasticsearch then, according to yauuie's [PR](https://github.com/elastic/logstash/pull/14299) ...

Workaround: without this patch, the Elasticsearch field's mapping would need to be adapted to _add_ `date_time_no_millis` , which accepts a value that does _not_ have fractional digits

---

<div class="post-metadata">

**Author:** ![Samuel\_Delepiere](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/samuel_delepiere/32/75345_2.png) [@Samuel\_Delepiere](https://discuss.elastic.co/u/Samuel_Delepiere)\
**Post date:** [March 15, 2023, 6:05pm UTC](https://discuss.elastic.co/t/logstash-date-filter-truncating-milliseconds-when-they-are-set-to-000/327770/3 "2023-03-15T18:05:44Z")

</div>

Thanks for the details. I'll just upgrade. No worries

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2023, 6:06pm UTC](https://discuss.elastic.co/t/logstash-date-filter-truncating-milliseconds-when-they-are-set-to-000/327770/4 "2023-04-12T18:06:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
