# Logstash Does not extract timestamp from JSON

**URL:** <https://discuss.elastic.co/t/logstash-does-not-extract-timestamp-from-json/52151>\
**Category:** Logstash\
**Created:** [June 8, 2016, 5:04am UTC](https://discuss.elastic.co/t/logstash-does-not-extract-timestamp-from-json/52151 "2016-06-08T05:04:58Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sunnysharma](https://avatars.discourse-cdn.com/v4/letter/s/ed8c4c/32.png) [@sunnysharma](https://discuss.elastic.co/u/sunnysharma)\
**Post date:** [June 8, 2016, 5:04am UTC](https://discuss.elastic.co/t/logstash-does-not-extract-timestamp-from-json/52151/1 "2016-06-08T05:04:58Z")

</div>

Hi Folks,

Logstash noob here. I am trying to put some JSON data but logstash is not setting my log data timestamp to @timestamp field. It continues to use the time when the data is read into logstash.

Here's the log data  
`{ "event_ts": "2016-Jun-07 20:13:51", "property": "propname", "aftype": "unicast" }`

Below are is my conf file:  
`
input {
stdin{}
}`

filter {  
date {  
match =\> ["event\_ts", "YYYY-MM-dd HH:mm:ss,SSS Z"]  
}  
}

output {  
stdout {  
codec =\> rubydebug  
}  
}

Output:  
{"event\_ts": "2016-Jun-07 20:13:51.987", "property": "numRoutes", "aftype": "ipv4-ucast"}  
{  
"message" =\> "{"event\_ts": "2016-Jun-07 20:13:51.987", "property": "numRoutes", "aftype": "ipv4-ucast"}",  
"@version" =\> "1",  
"@timestamp" =\> "2016-06-08T04:06:45.565Z",  
"host" =\> "skaliann-ucs-e1"  
}

@timestamp field is not the UTC equivalent of event\_ts.

What am I doing wrong here? Please help.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 8, 2016, 8:23pm UTC](https://discuss.elastic.co/t/logstash-does-not-extract-timestamp-from-json/52151/2 "2016-06-08T20:23:18Z")

</div>

As far as I can see (without having had time to test anything) there are a couple of issues. Firstly you have not used a json codec or filter to parse the JSON coming in, which means that the `event_ts` field has not been extracted and does not exist. In addition to this I don't think your date pattern in the date filter matches what you actually are passing in as you 1) have a three letter month instead of 2 digits, 2) there is a period instead of a comma before the milliseconds and 3) you are not supplying a time zone.

---

<div class="post-metadata">

**Author:** ![YLombardi](https://avatars.discourse-cdn.com/v4/letter/y/43a26b/32.png) [@YLombardi](https://discuss.elastic.co/u/YLombardi)\
**Post date:** [June 9, 2016, 7:00am UTC](https://discuss.elastic.co/t/logstash-does-not-extract-timestamp-from-json/52151/3 "2016-06-09T07:00:21Z")

</div>

In my filter I use this :

```
date {
  match => ["myTimestamp", "yyyy-MM-dd-HH.mm.ss.SSSSSS"]
  target => "@timestamp"
} 

```

I think you need to set the target attribute.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 12, 2016, 11:20am UTC](https://discuss.elastic.co/t/logstash-does-not-extract-timestamp-from-json/52151/4 "2016-06-12T11:20:42Z")

</div>

> I think you need to set the target attribute.

Only if the target field is something other than `@timestamp`.

---

<div class="post-metadata">

**Author:** ![sagittarius](https://avatars.discourse-cdn.com/v4/letter/s/94ad74/32.png) [@sagittarius](https://discuss.elastic.co/u/sagittarius)\
**Post date:** [February 15, 2017, 2:54pm UTC](https://discuss.elastic.co/t/logstash-does-not-extract-timestamp-from-json/52151/5 "2017-02-15T14:54:38Z")

</div>

Hi,  
I am also a newbie and I am trying to setup filebeat-\>logstash-\>elasticsearch chain and I am having problems with @timestamp which is not being transferred from the logfile and a timestamp when the message arrives into logstash is used instead. I will describe it on the example below. I hope somebody will help me understanding this problem and correcting it.

**Logfile has this format:**  
`{"application":"MyTestApp","source_host":"apphost01","message":"Hello_World","@timestamp":"2017-02-14T11:38:32.257Z"}`

**filebeat.yml:**  
`filebeat.prospectors: - input_type: log paths: - /tmp/json.log output.logstash: hosts: ["localhost:5043"]`

**logstash pipeline conf:**  
`input { beats { port => "5043" codec => json type => "log4j-json" } } output { stdout { codec => rubydebug } }`

**This is the logstash's output: (notice the @timestamp is different than one in the log entry)**  
`{ "source_host" => "apphost01", "@timestamp" => 2017-02-15T14:47:57.593Z, "application" => "MyTestApp", "offset" => 118, "@version" => "1", "input_type" => "log", "beat" => { "hostname" => "tpl450", "name" => "tpl450", "version" => "5.2.1" }, "host" => "tpl450", "source" => "/tmp/json.log", "message" => "Hello_World", "type" => "log", "tags" => [[0] "beats_input_codec_json_applied" ] }`

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 15, 2017, 6:17pm UTC](https://discuss.elastic.co/t/logstash-does-not-extract-timestamp-from-json/52151/6 "2017-02-15T18:17:32Z")

</div>

@sagittarius, please start your own topic for your problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:28am UTC](https://discuss.elastic.co/t/logstash-does-not-extract-timestamp-from-json/52151/7 "2017-07-06T04:28:35Z")

</div>


