# Logstash JSON parsing of @timestamp

**URL:** <https://discuss.elastic.co/t/logstash-json-parsing-of-timestamp/142476>\
**Category:** Logstash\
**Created:** [August 1, 2018, 6:41am UTC](https://discuss.elastic.co/t/logstash-json-parsing-of-timestamp/142476 "2018-08-01T06:41:39Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mykael](https://avatars.discourse-cdn.com/v4/letter/m/ec9cab/32.png) [@mykael](https://discuss.elastic.co/u/mykael)\
**Post date:** [August 1, 2018, 6:41am UTC](https://discuss.elastic.co/t/logstash-json-parsing-of-timestamp/142476/1 "2018-08-01T06:41:39Z")

</div>

The docs for the logstrash JSON plugin say:

> If the parsed data contains a @timestamp field, we will try to use it for the event’s @timestamp, if the parsing fails, the field will be renamed to \_@timestamp and the event will be tagged with a \_timestampparsefailure.

...but I can't find any info on how they try to parse it or how to affect the parsing.

I'm feeding in a record with @timestamp set to a valid epoch time - and it's failing to parse it:

` "@timestamp":"1522458058"`

Now, it's about 3 months old (old test data), but it is the correct timestamp for the event - 2018-03-31 01.00.58 am - so why is it getting rejected?

Is there anyway of disabling the timestamp parsing? I'm trying to feed logstash data it can simply ingest without it needing to mess around with each record after it's received it.

---

<div class="post-metadata">

**Author:** ![mykael](https://avatars.discourse-cdn.com/v4/letter/m/ec9cab/32.png) [@mykael](https://discuss.elastic.co/u/mykael)\
**Post date:** [August 1, 2018, 7:17am UTC](https://discuss.elastic.co/t/logstash-json-parsing-of-timestamp/142476/2 "2018-08-01T07:17:08Z")

</div>

I get the same problem without the quotes around the number.

---

<div class="post-metadata">

**Author:** ![tgaudin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tgaudin/32/32583_2.png) [@tgaudin](https://discuss.elastic.co/u/tgaudin)\
**Post date:** [August 1, 2018, 8:07am UTC](https://discuss.elastic.co/t/logstash-json-parsing-of-timestamp/142476/3 "2018-08-01T08:07:36Z")

</div>

Does it work if you parse `_@timestamp` with a date filter afterwards? I don't know if the json filter is super clever at detecting the date format.

Something like this should work:

```auto
if "_timestampparsefailure" in [tags] {
  date {
    match => ["_@timestamp", "UNIX"]
    remove_field => "_@timestamp"
    remove_tag => "_timestampparsefailure"
  }
}

```

If the question is just about disabling the parsing (and not caring about the correct timestamp for the event), I don't know, and I don't see a way in the code to do that.

---

<div class="post-metadata">

**Author:** ![mykael](https://avatars.discourse-cdn.com/v4/letter/m/ec9cab/32.png) [@mykael](https://discuss.elastic.co/u/mykael)\
**Post date:** [August 1, 2018, 3:18pm UTC](https://discuss.elastic.co/t/logstash-json-parsing-of-timestamp/142476/4 "2018-08-01T15:18:13Z")

</div>

Yeah, that works. Probably a little more efficient just to put the epoch value in a different field and just catch it with a date filter.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 1, 2018, 4:03pm UTC](https://discuss.elastic.co/t/logstash-json-parsing-of-timestamp/142476/5 "2018-08-01T16:03:14Z")

</div>

> [@mykael](#):
>
> ...but I can't find any info on how they try to parse it or how to affect the parsing

It is not documented as far as I can see. You would have to dig in to the [source](https://github.com/logstash-plugins/logstash-filter-json/blob/d9c948268f4e1524b78fce664a743ff4b57dad7a/lib/logstash/filters/json.rb#L100) to see how coercion to a DateTime works.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 29, 2018, 4:03pm UTC](https://discuss.elastic.co/t/logstash-json-parsing-of-timestamp/142476/6 "2018-08-29T16:03:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
