# Overwrite @timestamp field

**URL:** <https://discuss.elastic.co/t/overwrite-timestamp-field/352212>\
**Category:** Logstash\
**Created:** [January 31, 2024, 4:24pm UTC](https://discuss.elastic.co/t/overwrite-timestamp-field/352212 "2024-01-31T16:24:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rmoss25](https://avatars.discourse-cdn.com/v4/letter/r/b4bc9f/32.png) [@rmoss25](https://discuss.elastic.co/u/rmoss25)\
**Post date:** [January 31, 2024, 4:24pm UTC](https://discuss.elastic.co/t/overwrite-timestamp-field/352212/1 "2024-01-31T16:24:53Z")

</div>

Hi,  
I am trying to overwrite the @timestamp filed with the time from the log source but logstash fails to start when trying to run. I am guessing it has something to do with the "-04" in the time.....see below time from the actual log

2022-08-30 12:34:38.88910-04

I am breaking it out as but I believe the "INT" is causing me issues.

%{YEAR}-%{MONTHNUM}-%{MONTHDAY} %{HOUR}:%{MINUTE}:%{SECOND}.%{INT}-%{INT}

```auto
input {
   tcp {
   port => 8090
   tags => ["custom_app1"] 
   codec => json { }
  }
}

filter
{
grok {

        pattern_definitions => {
			"customtime" => "%{YEAR}-%{MONTHNUM}-%{MONTHDAY} %{HOUR}:%{MINUTE}:%{SECOND}.%{INT}-%{INT}"
			"customtime2" => "%{HOUR}:%{MINUTE}:%{SECOND}"
				}
         match => { "message" => ["%{customtime:timestamp} %{customtime2:session_endtime} %{WORD:log_level} %{NOTSPACE:sessions_id} %{GREEDYDATA:action}\s\{\"\id\"\:%{NUMBER:id}\,\D+%{NUMBER:to_be_assigned}\,\D+\:\"%{NOTSPACE:user_name}\"\,\"\w+\"\:\[%{GREEDYDATA:to_be_unassigned}\,\"\:\[\{\"\w+\"\:%{NUMBER:id2}\,\"\w+\"\:\"%{GREEDYDATA:category}\"\}\,\{\"\w+\"\:%{GREEDYDATA:id3}\]\}\,\"\w+\"\:\"%{GREEDYDATA:user_role}\"%{GREEDYDATA:rest_msg}" ] }

        }
		
date {
        locale => "$LANG"
        match => ["timestamp", "YYYY-MM-DD HH:MM:SS.SSSSSS-TZ"]
        target => "@timestamp"
      }	

}

output {
# elasticsearch { hosts => ["localhost:9200"] }
  stdout { codec => rubydebug }

}

```

The timestamp is written to the timestamp field as follows  
"timestamp" =\> "2022-08-30 12:34:38.88910-04"

I feel like this "YYYY-MM-DD HH:MM:SS.SSSSSS-TZ" is causing me issues

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 31, 2024, 5:03pm UTC](https://discuss.elastic.co/t/overwrite-timestamp-field/352212/2 "2024-01-31T17:03:58Z")

</div>

This works:  
`match => ["timestamp", ""yyyy-MM-dd HH:mm:ss.SSSSSZ"] `

Result:  
"@timestamp" =\> 2022-08-30T16:34:38.889Z

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 28, 2024, 5:04pm UTC](https://discuss.elastic.co/t/overwrite-timestamp-field/352212/3 "2024-02-28T17:04:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
