# Mutate timestamp for nginx logs

**URL:** <https://discuss.elastic.co/t/mutate-timestamp-for-nginx-logs/104814>\
**Category:** Logstash\
**Created:** [October 22, 2017, 6:17pm UTC](https://discuss.elastic.co/t/mutate-timestamp-for-nginx-logs/104814 "2017-10-22T18:17:34Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![gotjoshua](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gotjoshua/32/23102_2.png) [@gotjoshua](https://discuss.elastic.co/u/gotjoshua)\
**Post date:** [October 23, 2017, 8:14am UTC](https://discuss.elastic.co/t/mutate-timestamp-for-nginx-logs/104814/3 "2017-10-23T08:14:37Z")

</div>

Hey @magnusbaeck, no my code with stashed\_time is working fine.

I had the problem when I tried the suggestion that I referenced from the old thread:

```
mutate {
      add_field => { "read_timestamp" => "@timestamp" }
   }

```

I am continuing the thread now, to offer a solution that seems to work with 6.0 and to ask if there was a syntax change from 5.6.

Either way, this indicates that [the docs need an update](https://www.elastic.co/guide/en/logstash/6.0/logstash-config-for-filebeat-modules.html#parsing-nginx), as they are renaming the @timestamp field without adding a new field - which can lead to "no timestamp field errors"

I see that you [also engaged in the previous thread](https://discuss.elastic.co/t/keep-logstash-from-crashing/90392/4?u=gotjoshua), @magnusbaeck... In general, do you recommend to remove the date from the default index?

Thanks for the help, still finding my way into the world of ELK+beats

---

_[View the full topic](https://discuss.elastic.co/t/mutate-timestamp-for-nginx-logs/104814)._
