# My Kibana dashboard has Kibana processed time stamp , instead I want source log file time stamp

**URL:** <https://discuss.elastic.co/t/my-kibana-dashboard-has-kibana-processed-time-stamp-instead-i-want-source-log-file-time-stamp/221737>\
**Category:** Elasticsearch\
**Created:** [March 2, 2020, 4:48pm UTC](https://discuss.elastic.co/t/my-kibana-dashboard-has-kibana-processed-time-stamp-instead-i-want-source-log-file-time-stamp/221737 "2020-03-02T16:48:34Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![pjvijay](https://avatars.discourse-cdn.com/v4/letter/p/9fc348/32.png) [@pjvijay](https://discuss.elastic.co/u/pjvijay)\
**Post date:** [March 2, 2020, 4:48pm UTC](https://discuss.elastic.co/t/my-kibana-dashboard-has-kibana-processed-time-stamp-instead-i-want-source-log-file-time-stamp/221737/1 "2020-03-02T16:48:34Z")

</div>

Hello All

Seems the issue is simple , but struggling from long time.

I want to view my Source log time stamp in the Kibana dashboard intead of Kibana processed time .  
As I want to visualize using Log time stamp and the count of a result code(varies from 0 to 12 numerical value ) from my log file.

Below are the current files I am using :

Log content for the source log file for date or time format:

2020-02-10 12:21:52.4835|ERROR|d\_\_9.MoveNext|A task was canceled., jsonInput: {"ResourceID":288,"RequestID":"6371693410848345290038190","Data":null,"Result":0}, apiURL: [http://sm2cf1.on.bell.ca:8087/IID\_IVRScheduler\_WS/rest/Dialer/Hangup](http://sm2cf1.on.bell.ca:8087/IID_IVRScheduler_WS/rest/Dialer/Hangup)

Below is the logstash.conf ,I am using currently:

input {  
beats {  
port =\> 5044  
}  
}

filter {  
grok {  
patterns\_dir =\> ["../pattern"]  
match =\> { "message" =\> "%{LongDate:longdate}|%{EventType:eventtype}|%{CallSite:callsite}|%{Message:message}, Result: %{ResultCode:resultcode}" }  
match =\> { "message" =\> "%{LongDate:longdate}|%{EventType:eventtype}|%{CallSite:callsite}|%{Message:message} ==\> Result: %{ResultCode:resultcode}" }  
match =\> { "message" =\> "%{LongDate:longdate}|%{EventType:eventtype}|%{CallSite:callsite}|%{Message:message}" }  
match =\> { "message" =\> "%{LongDate:longdate}|%{EventType:eventtype}|%{CallSite:callsite}|%{Message:message}.," }

```
}

```

date {  
match =\> ["longdate", "ISO8601"]  
target =\> "@timestamp"  
}  
}

output {  
elasticsearch {  
hosts =\> "localhost:9200"  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

Pattern:

LongDate \d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}.\d{4}  
EventType ERROR|FATAL|INFO|TRACE  
CallSite %{GREEDYDATA}  
Message %{GREEDYDATA}  
ResultCode %{GREEDYDATA}

LongDate \d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}.\d{4}  
EventType ERROR|FATAL|INFO|TRACE  
CallSite %{GREEDYDATA}  
Message %{GREEDYDATA}

Please advise.

Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2020, 4:48pm UTC](https://discuss.elastic.co/t/my-kibana-dashboard-has-kibana-processed-time-stamp-instead-i-want-source-log-file-time-stamp/221737/2 "2020-03-30T16:48:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
