# Overwriting json @timestamp

**URL:** <https://discuss.elastic.co/t/overwriting-json-timestamp/94631>\
**Category:** Logstash\
**Created:** [July 26, 2017, 11:48am UTC](https://discuss.elastic.co/t/overwriting-json-timestamp/94631 "2017-07-26T11:48:13Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![2knarf](https://avatars.discourse-cdn.com/v4/letter/2/6a8cbe/32.png) [@2knarf](https://discuss.elastic.co/u/2knarf)\
**Post date:** [July 26, 2017, 11:48am UTC](https://discuss.elastic.co/t/overwriting-json-timestamp/94631/1 "2017-07-26T11:48:13Z")

</div>

Hello, I am sending json logs to logstash and I want to overwrite the @timestamp field.

To do this I do:

json.keys\_under\_root: true  
json.overwrite\_keys: true

The log entries goes to logstash, but in Kibana the @timestamp field is not overwritten and shows the error:

@timestamp not overwritten (parse error on 2017-06-02T21:40:59+0000)

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 26, 2017, 12:02pm UTC](https://discuss.elastic.co/t/overwriting-json-timestamp/94631/2 "2017-07-26T12:02:48Z")

</div>

It looks like Go's RFC3389 time parser is failing on that timestamp. [This](https://play.golang.org/p/EL_T4Q3c8I) recreates the issue. The full error is:

```
parsing time "2017-06-02T21:40:59+0000" as "2006-01-02T15:04:05Z07:00": cannot parse "+0000" as "Z07:00"

```

Maybe the time parser should be a bit more robust and try a few more common formats.

For now you will need to use Logstash to handle this.

---

<div class="post-metadata">

**Author:** ![2knarf](https://avatars.discourse-cdn.com/v4/letter/2/6a8cbe/32.png) [@2knarf](https://discuss.elastic.co/u/2knarf)\
**Post date:** [July 26, 2017, 12:24pm UTC](https://discuss.elastic.co/t/overwriting-json-timestamp/94631/3 "2017-07-26T12:24:00Z")

</div>

Thank you!

Do you have any suggestions on how I can fix this with logstash?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 26, 2017, 9:36pm UTC](https://discuss.elastic.co/t/overwriting-json-timestamp/94631/4 "2017-07-26T21:36:49Z")

</div>

One way would be to do the JSON decoding in Logstash. Then apply a date filter.

```auto
filter {
  json {
    source => "message"
  }
  date {
     # Add config here for parsing the date.
  }
}

```

[https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html#plugins-filters-json-source](https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html#plugins-filters-json-source)  
[https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html#plugins-filters-date-target](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html#plugins-filters-date-target)

---

<div class="post-metadata">

**Author:** ![2knarf](https://avatars.discourse-cdn.com/v4/letter/2/6a8cbe/32.png) [@2knarf](https://discuss.elastic.co/u/2knarf)\
**Post date:** [July 27, 2017, 9:26am UTC](https://discuss.elastic.co/t/overwriting-json-timestamp/94631/5 "2017-07-27T09:26:06Z")

</div>

I added this now, but I still get the same error message:

> input {  
> beats {  
> port =\> 5445  
> codec =\> "json"  
> ssl =\> true  
> ssl\_certificate =\> "/etc/logstash/logstash.crt"  
> ssl\_key =\> "/etc/logstash/logstash.key"  
> }  
> }

> filter {  
> json {  
> source =\> "message"  
> }  
> date {  
> match =\> ["timestamp", "ISO8601"]  
> }  
> }

---

<div class="post-metadata">

**Author:** ![josephjohney](https://avatars.discourse-cdn.com/v4/letter/j/eada6e/32.png) [@josephjohney](https://discuss.elastic.co/u/josephjohney)\
**Post date:** [July 27, 2017, 10:06am UTC](https://discuss.elastic.co/t/overwriting-json-timestamp/94631/6 "2017-07-27T10:06:45Z")

</div>

Try using@timestamp instead

---

<div class="post-metadata">

**Author:** ![2knarf](https://avatars.discourse-cdn.com/v4/letter/2/6a8cbe/32.png) [@2knarf](https://discuss.elastic.co/u/2knarf)\
**Post date:** [July 27, 2017, 10:26am UTC](https://discuss.elastic.co/t/overwriting-json-timestamp/94631/7 "2017-07-27T10:26:50Z")

</div>

This made no difference.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 27, 2017, 3:00pm UTC](https://discuss.elastic.co/t/overwriting-json-timestamp/94631/8 "2017-07-27T15:00:01Z")

</div>

> [@2knarf](#):
>
> codec =\> "json"

Remove that line.

---

<div class="post-metadata">

**Author:** ![2knarf](https://avatars.discourse-cdn.com/v4/letter/2/6a8cbe/32.png) [@2knarf](https://discuss.elastic.co/u/2knarf)\
**Post date:** [July 28, 2017, 8:06am UTC](https://discuss.elastic.co/t/overwriting-json-timestamp/94631/9 "2017-07-28T08:06:43Z")

</div>

Hi, thanks for the suggestion, but this did not make any difference.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 28, 2017, 3:46pm UTC](https://discuss.elastic.co/t/overwriting-json-timestamp/94631/10 "2017-07-28T15:46:29Z")

</div>

Did you disable the JSON parsing on the Beats side?

---

<div class="post-metadata">

**Author:** ![2knarf](https://avatars.discourse-cdn.com/v4/letter/2/6a8cbe/32.png) [@2knarf](https://discuss.elastic.co/u/2knarf)\
**Post date:** [July 28, 2017, 4:07pm UTC](https://discuss.elastic.co/t/overwriting-json-timestamp/94631/11 "2017-07-28T16:07:53Z")

</div>

Yes, tried with and without.

---

<div class="post-metadata">

**Author:** ![2knarf](https://avatars.discourse-cdn.com/v4/letter/2/6a8cbe/32.png) [@2knarf](https://discuss.elastic.co/u/2knarf)\
**Post date:** [July 28, 2017, 4:11pm UTC](https://discuss.elastic.co/t/overwriting-json-timestamp/94631/12 "2017-07-28T16:11:50Z")

</div>

Can this be due to the timestamp beeing

2017-06-02T21:40:59+0000

And not

2017-06-02T21:40:59+00:00

Which is the correct ISO8601 format?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 25, 2017, 4:11pm UTC](https://discuss.elastic.co/t/overwriting-json-timestamp/94631/13 "2017-08-25T16:11:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
