# Parsing log date into timestamp

**URL:** <https://discuss.elastic.co/t/parsing-log-date-into-timestamp/293966>\
**Category:** Logstash\
**Created:** [January 11, 2022, 4:36am UTC](https://discuss.elastic.co/t/parsing-log-date-into-timestamp/293966 "2022-01-11T04:36:19Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![phung025](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/phung025/32/97585_2.png) [@phung025](https://discuss.elastic.co/u/phung025)\
**Post date:** [January 11, 2022, 4:36am UTC](https://discuss.elastic.co/t/parsing-log-date-into-timestamp/293966/1 "2022-01-11T04:36:19Z")

</div>

In the JSON-format logs sent from filebeat to logstash, I have a field named "time". In the logstash.conf, I mutate it to create a field in the kibana log called rawDate

logstash.conf:

```auto
mutate {
    add_field => {"rawDate" => "%{[parsed_json][time]}"}
}

```

Now the log on Kibana has 2 fields that look like this:

@timestamp Jan 11, 2022 @ 11:09:46.817  
rawDate Mon Jan 10 2022 23:09:32 GMT-0500 (Eastern Standard Time)

I'm trying to parse the rawData to replace the @timestamp but couldn't figure out how to do it. Inside the logstash.conf, I tried to add this but it didn't work:

```auto
date {
    match => ["time", "EEE MMM dd yyyy HH:mm:ss ZZZ"]
    target => "@timestamp"
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 11, 2022, 1:31pm UTC](https://discuss.elastic.co/t/parsing-log-date-into-timestamp/293966/2 "2022-01-11T13:31:07Z")

</div>

> [@phung025](#):
>
> ```auto
> date {
> match => ["time", "EEE MMM dd yyyy HH:mm:ss ZZZ"]
> 
> ```

ZZZ matches the ids listed on the Joda [TZ page](http://joda-time.sourceforge.net/timezones.html). You will need to modify the string before trying to parse it.

```
    mutate { add_field => { "rawDate" => "Mon Jan 10 2022 23:09:32 GMT-0500 (Eastern Standard Time)" } }
    mutate { gsub => ["rawDate", " \(Eastern \w+ Time\)", "", "rawDate", "GMT", "Etc/GMT", "rawDate", "-0(\d)00", "-\1"] }
    date { match => ["rawDate", "EEE MMM dd yyyy HH:mm:ss ZZZ"] }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 8, 2022, 1:31pm UTC](https://discuss.elastic.co/t/parsing-log-date-into-timestamp/293966/3 "2022-02-08T13:31:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
