# Mapping timestamp in Kibana

**URL:** <https://discuss.elastic.co/t/mapping-timestamp-in-kibana/219581>\
**Category:** Elasticsearch\
**Created:** [February 17, 2020, 8:30am UTC](https://discuss.elastic.co/t/mapping-timestamp-in-kibana/219581 "2020-02-17T08:30:32Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ilija\_Angeloski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ilija_angeloski/32/53754_2.png) [@Ilija\_Angeloski](https://discuss.elastic.co/u/Ilija_Angeloski)\
**Post date:** [February 17, 2020, 8:30am UTC](https://discuss.elastic.co/t/mapping-timestamp-in-kibana/219581/1 "2020-02-17T08:30:33Z")

</div>

Hi, I have problem mapping timestamp field. I have field in my csv file timestamp that have values like 1545003901, 1543347920 etc... In kibana in dev tools i type  
"properties":{  
"timestamp":{  
"type" : "date"  
"format": "epoch\_millis"  
}  
}  
But it is giving me year 1970. I know that this epoch have something to do with the year of 1970, but is there any way to format these type of timestamps? How can I have the correct date of the timestamp? Should I convert it somehow when I ingest it in logstash?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 17, 2020, 10:40am UTC](https://discuss.elastic.co/t/mapping-timestamp-in-kibana/219581/2 "2020-02-17T10:40:45Z")

</div>

You may want to use `epoch_second` instead of `epoch_millis`, as your data looks like it is missing the millisecond granularity.

---

<div class="post-metadata">

**Author:** ![Ilija\_Angeloski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ilija_angeloski/32/53754_2.png) [@Ilija\_Angeloski](https://discuss.elastic.co/u/Ilija_Angeloski)\
**Post date:** [February 17, 2020, 11:06am UTC](https://discuss.elastic.co/t/mapping-timestamp-in-kibana/219581/3 "2020-02-17T11:06:08Z")

</div>

Also tried that, but it says failed to parse date field with format epoch\_second

 ![index](https://us1.discourse-cdn.com/elastic/original/3X/a/7/a79900305c9bbb30fe71b8ae16d56446ab5adfff.png) This is the logstash conf file

 ![1](https://us1.discourse-cdn.com/elastic/original/3X/c/3/c3d6ac9e4ecf1bd3d4571929995c765af4fad9be.png) and this is the mapping that I do in kibana

Its says could not parse field time stamp with this format [epoch\_second]

And this is how my timestamp field looks like

 ![2](https://us1.discourse-cdn.com/elastic/original/3X/4/6/46aabd25e2abbec118b84d52d2ed22fefa16718a.png)

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 17, 2020, 1:05pm UTC](https://discuss.elastic.co/t/mapping-timestamp-in-kibana/219581/4 "2020-02-17T13:05:39Z")

</div>

Please do not post screenshots, but real code snippets.

Can you create a fully reproducible **minimal** example, so others can follow this issue and retry it on their own? Otherwise helping will be hard without any further information like error messages.

---

<div class="post-metadata">

**Author:** ![Ilija\_Angeloski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ilija_angeloski/32/53754_2.png) [@Ilija\_Angeloski](https://discuss.elastic.co/u/Ilija_Angeloski)\
**Post date:** [February 17, 2020, 1:22pm UTC](https://discuss.elastic.co/t/mapping-timestamp-in-kibana/219581/5 "2020-02-17T13:22:39Z")

</div>

Sure,

Conf file:

input{  
stdin{}   
}  
filter{  
csv{  
separator=\>","  
columns=\>['temp', 'location', 'clouds', 'pressure', 'rain', 'time\_stamp', 'humidity', 'wind']  
}  
}  
output{  
elasticsearch{  
hosts=\>["localhost:9200"]  
index=\>"weathertest"  
}  
stdout{codec =\> rubydebug}  
}

Input data:  
42.42, Back Bay, 1, 1012.14, 0.1228, 1545003901, 0.77, 11.25

Mapping dev tools kibana:

PUT weathertest/\_mappings  
{  
"properties": {  
"temp": {  
"type": "float"  
},  
"clouds":{  
"type": "float"  
},  
"pressure":{  
"type": "float"  
},  
"rain": {  
"type": "float"  
},  
"time\_stamp": {  
"type": "date",  
"format": "epoch\_second"  
},  
"humidity": {  
"type": "float"  
},  
"wind": {  
"type": "float"  
}  
}

}

Here is minimal example.  
Just to recap, the problem is the time\_stamp field, which I want to convert do date, when I try with epoch\_millis it creates with year 1970, when I use epoch\_second it cant parse the field.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 17, 2020, 2:41pm UTC](https://discuss.elastic.co/t/mapping-timestamp-in-kibana/219581/6 "2020-02-17T14:41:04Z")

</div>

Please use proper formatting, when copying text snippets, this is really hard to read. This forum supports markdown, so formatting code snippets is quite easy.

I think the problem is with your data. When using the csv filter, you data gets split and the data in question will become `1545003901`- but with a space in the beginning. This is not part of your mapping configuration for the date and thus throws an error. I am pretty sure that this shows up in your logstash output.

The solution to this is to get rid of the space in the beginning. You can try and split by `, ` with a space at the end and see if that works, or you will have to trim your data.

---

<div class="post-metadata">

**Author:** ![Ilija\_Angeloski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ilija_angeloski/32/53754_2.png) [@Ilija\_Angeloski](https://discuss.elastic.co/u/Ilija_Angeloski)\
**Post date:** [February 19, 2020, 5:30pm UTC](https://discuss.elastic.co/t/mapping-timestamp-in-kibana/219581/7 "2020-02-19T17:30:02Z")

</div>

Worked thanks 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 18, 2020, 5:30pm UTC](https://discuss.elastic.co/t/mapping-timestamp-in-kibana/219581/8 "2020-03-18T17:30:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
