# One(1) date-field as default in index templates is not enough, or is it?

**URL:** <https://discuss.elastic.co/t/one-1-date-field-as-default-in-index-templates-is-not-enough-or-is-it/159012>\
**Category:** Beats\
**Created:** [December 1, 2018, 6:02pm UTC](https://discuss.elastic.co/t/one-1-date-field-as-default-in-index-templates-is-not-enough-or-is-it/159012 "2018-12-01T18:02:27Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![antwan](https://avatars.discourse-cdn.com/v4/letter/a/dbc845/32.png) [@antwan](https://discuss.elastic.co/u/antwan)\
**Post date:** [December 1, 2018, 6:02pm UTC](https://discuss.elastic.co/t/one-1-date-field-as-default-in-index-templates-is-not-enough-or-is-it/159012/1 "2018-12-01T18:02:27Z")

</div>

It would be beneficial to have one more, i.e:  
`@timestamp` when the logs are written, solves the question "When did the incident occur?"  
`@received_at` when the logs are read, solves the question "When did we know the incident occurred?"

What are your thoughts?

Having to manually manipulate index templates, input filters and so forth every upgrade gets old fast for an application maintainer.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 30, 2018, 7:49am UTC](https://discuss.elastic.co/t/one-1-date-field-as-default-in-index-templates-is-not-enough-or-is-it/159012/3 "2018-12-30T07:49:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
