# Logstash update @timestamp

**URL:** <https://discuss.elastic.co/t/logstash-update-timestamp/77816>\
**Category:** Logstash\
**Created:** [March 8, 2017, 1:00pm UTC](https://discuss.elastic.co/t/logstash-update-timestamp/77816 "2017-03-08T13:00:39Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Exocomp](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Exocomp](https://discuss.elastic.co/u/Exocomp)\
**Post date:** [March 8, 2017, 1:00pm UTC](https://discuss.elastic.co/t/logstash-update-timestamp/77816/1 "2017-03-08T13:00:39Z")

</div>

Hi,

I have a field that is already a datetime field:

```
"last_execution_time" => 2017-03-08T12:19:14.593Z,

```

I would like this field to be the value of @timestamp.

When I try:

```
		mutate {
		update => { "@timestamp" => "%{last_execution_time}" }
	}

```

Logstash crashes with:

```
06:55:20.695 [LogStash::Runner] FATAL logstash.runner - An unexpected error occurred! {:error=>#<TypeError: wrong argument type String (expected LogStash::Timestamp)

```

The error is clear that it is trying to use string for @timestamp but is failing, but how do I tell it not to convert it to string as it is not a string type to begin with ?

I also tried this:

```
		date { 
		match => ["last_execution_time", "ISO8601"]
		timezone => "UTC"
	}

```

But this does not update the @timestamp field:

```
"last_execution_time" => 2017-03-08T12:19:14.593Z,
"@timestamp" => 2017-03-08T12:58:20.476Z,

```

Thanks,  
E

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 9, 2017, 12:42pm UTC](https://discuss.elastic.co/t/logstash-update-timestamp/77816/2 "2017-03-09T12:42:08Z")

</div>

In the latter case, what error message are you getting in your log?

---

<div class="post-metadata">

**Author:** ![Exocomp](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Exocomp](https://discuss.elastic.co/u/Exocomp)\
**Post date:** [March 9, 2017, 2:55pm UTC](https://discuss.elastic.co/t/logstash-update-timestamp/77816/3 "2017-03-09T14:55:47Z")

</div>

@magnusbaeck

There is no error in the log in regards to the latter case, it executes fine but the value of last\_execution\_time does not match @timestamp.

Any other recommendations in troubleshooting ?

Side Note: I'm using the default configuration, calling the binary directly, which logs to the screen. Then checking each line in the console for any errors.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 9, 2017, 3:00pm UTC](https://discuss.elastic.co/t/logstash-update-timestamp/77816/4 "2017-03-09T15:00:14Z")

</div>

That's odd. Try bumping up the log level. I'm pretty sure the date filter will log all parse errors.

---

<div class="post-metadata">

**Author:** ![Exocomp](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Exocomp](https://discuss.elastic.co/u/Exocomp)\
**Post date:** [March 9, 2017, 3:08pm UTC](https://discuss.elastic.co/t/logstash-update-timestamp/77816/5 "2017-03-09T15:08:43Z")

</div>

@magnusbaeck

Although there was no error in the log as an exception. I do see the following in the tags which I just noticed:

```
[0] "_dateparsefailure",

```

Hmm, ok, so ISO8601 should match the pattern right? However, it is already a date type not a string to parse, does that make a difference with the date filter ?

Let me see what log level it is using by default and increase that maybe that will produce a better error.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 9, 2017, 3:11pm UTC](https://discuss.elastic.co/t/logstash-update-timestamp/77816/6 "2017-03-09T15:11:00Z")

</div>

Aha, right. Yeah, if the field is a timestamp field the date filter won't work. You probably need to use a ruby filter to assign the timestamp field to `@timestamp`, or make sure the field is converted to a string before you feed it to the date filter.

---

<div class="post-metadata">

**Author:** ![Exocomp](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Exocomp](https://discuss.elastic.co/u/Exocomp)\
**Post date:** [March 9, 2017, 3:16pm UTC](https://discuss.elastic.co/t/logstash-update-timestamp/77816/7 "2017-03-09T15:16:37Z")

</div>

@magnusbaeck

Ruby ehh, ok, let me try.

---

<div class="post-metadata">

**Author:** ![Exocomp](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Exocomp](https://discuss.elastic.co/u/Exocomp)\
**Post date:** [March 9, 2017, 3:26pm UTC](https://discuss.elastic.co/t/logstash-update-timestamp/77816/8 "2017-03-09T15:26:29Z")

</div>

@magnusbaeck

Ok, ruby filter is the winner. This worked.

```
	ruby {
		code => "event.set('@timestamp', event.get('last_execution_time'));"
	} 

"last_execution_time" => 2017-03-09T04:07:51.520Z
"@timestamp" => 2017-03-09T04:07:51.520Z

```

Is that ok to use or do you know of a more optimal way ?

Thanks,  
E

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 9, 2017, 3:26pm UTC](https://discuss.elastic.co/t/logstash-update-timestamp/77816/9 "2017-03-09T15:26:56Z")

</div>

That looks okay.

---

<div class="post-metadata">

**Author:** ![Exocomp](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Exocomp](https://discuss.elastic.co/u/Exocomp)\
**Post date:** [March 9, 2017, 3:27pm UTC](https://discuss.elastic.co/t/logstash-update-timestamp/77816/10 "2017-03-09T15:27:28Z")

</div>

@magnusbaeck

You were very helpful, thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 6, 2017, 3:27pm UTC](https://discuss.elastic.co/t/logstash-update-timestamp/77816/11 "2017-04-06T15:27:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
