# Need Help Creating Logstash Filter to use timestamp in log message in Elastic/Kibana

**URL:** <https://discuss.elastic.co/t/need-help-creating-logstash-filter-to-use-timestamp-in-log-message-in-elastic-kibana/56502>\
**Category:** Logstash\
**Created:** [July 27, 2016, 10:32am UTC](https://discuss.elastic.co/t/need-help-creating-logstash-filter-to-use-timestamp-in-log-message-in-elastic-kibana/56502 "2016-07-27T10:32:53Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![darioc](https://avatars.discourse-cdn.com/v4/letter/d/bb73d2/32.png) [@darioc](https://discuss.elastic.co/u/darioc)\
**Post date:** [July 27, 2016, 10:32am UTC](https://discuss.elastic.co/t/need-help-creating-logstash-filter-to-use-timestamp-in-log-message-in-elastic-kibana/56502/1 "2016-07-27T10:32:53Z")

</div>

Hello,

Okay, I'm probably missing something pretty obvious.

I have a log message like the following:

INFO 2016-07-21 13:17:48,139 [http-bio-8080-exec-5] com.vendor.recserver.controller.RestController - site:company; abtest:none; pagetemplate:PT\_RelatedRec: Total Time = 1ms. widget:RecentlyViewedProduct time:0ms scanned:0 timebox:none fallback:0 of 5 widget:RelatedRec time:0ms scanned:4 timebox:none fallback:0 of 4 context-url:[http://www.company.com/eu/p/347340](http://www.company.com/eu/p/347340)

Trying to create the fields so that elastic and kibana can do their magic, but I'm not getting far

Here's my logstash configuration

filter {  
date {  
match =\> ["logtime", "ISO8601"]  
}  
grok {  
match =\> { "message" =\> "%{LOGLEVEL:severity} %{TIMESTAMP\_ISO8601:logtime} %{NOTSPACE:javathread} %{JAVACLASS:class} %{GREEDYDATA:therest}"  
}  
}  
}

In elastic search and kibana, the date is not being used to index. Here's the message in json output from kibana

{  
"\_index": "logstash-2016.07.27",  
"\_type": "logs",  
"\_id": "AVYr5KBDX2kxhEGTGKoW",  
"\_score": 1,  
"\_source": {  
"message": "INFO 2016-07-21 13:17:48,139 [http-bio-8080-exec-5] com.vendor.recserver.controller.RestController - site:company; abtest:none; pagetemplate:PT\_RelatedRec: Total Time = 1ms. widget:RecentlyViewedProduct time:0ms scanned:0 timebox:none fallback:0 of 5 widget:RelatedRec time:0ms scanned:4 timebox:none fallback:0 of 4 context-url:[http://www.company.com/eu/p/347340](http://www.company.com/eu/p/347340)",  
"@version": "1",  
"@timestamp": "2016-07-27T10:26:57.948Z",  
"host": "dc-lt-mbp15",  
"severity": "INFO",  
"logtime": "2016-07-21 13:17:48,139",  
"javathread": "[http-bio-8080-exec-5]",  
"class": "com.vendor.recserver.controller.RestController",  
"therest": "- site:company; abtest:none; pagetemplate:PT\_RelatedRec: Total Time = 1ms. widget:RecentlyViewedProduct time:0ms scanned:0 timebox:none fallback:0 of 5 widget:RelatedRec time:0ms scanned:4 timebox:none fallback:0 of 4 context-url:[http://www.company.com/eu/p/347340](http://www.company.com/eu/p/347340)"  
},  
"fields": {  
"@timestamp": [  
1469615217948  
]  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 27, 2016, 1:18pm UTC](https://discuss.elastic.co/t/need-help-creating-logstash-filter-to-use-timestamp-in-log-message-in-elastic-kibana/56502/2 "2016-07-27T13:18:26Z")

</div>

Filters are processed in the order they're listed. Your date filter uses the `logtime` field that's extracted by the grok filter so you need the grok filter to go first.

---

<div class="post-metadata">

**Author:** ![darioc](https://avatars.discourse-cdn.com/v4/letter/d/bb73d2/32.png) [@darioc](https://discuss.elastic.co/u/darioc)\
**Post date:** [July 27, 2016, 3:30pm UTC](https://discuss.elastic.co/t/need-help-creating-logstash-filter-to-use-timestamp-in-log-message-in-elastic-kibana/56502/3 "2016-07-27T15:30:16Z")

</div>

Hello Magnus,

Thank you for your reply. Yes, of course that worked. When I tried that before I thought it was not working because I forgot to look back using kibana! Once I realized that, I found that previous experiment had worked and I just had not looked for the properly time stamped message.

Thank you.

Cheers, Dario

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:46am UTC](https://discuss.elastic.co/t/need-help-creating-logstash-filter-to-use-timestamp-in-log-message-in-elastic-kibana/56502/4 "2017-07-06T04:46:16Z")

</div>


