# Problem with timestamp

**URL:** <https://discuss.elastic.co/t/problem-with-timestamp/72561>\
**Category:** Logstash\
**Created:** [January 24, 2017, 3:26am UTC](https://discuss.elastic.co/t/problem-with-timestamp/72561 "2017-01-24T03:26:06Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![satishsnv](https://avatars.discourse-cdn.com/v4/letter/s/76d3ee/32.png) [@satishsnv](https://discuss.elastic.co/u/satishsnv)\
**Post date:** [January 24, 2017, 3:26am UTC](https://discuss.elastic.co/t/problem-with-timestamp/72561/1 "2017-01-24T03:26:06Z")

</div>

hi i am using following filter to overwrite the @timestamp, but its not working. may i know the issue.

filter{  
date{  
match =\>["timeStamp", "EEE yyyy MMM dd HH:mm:ss:SSS"]  
remove\_field =\> ["timeStamp"]  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 24, 2017, 6:53am UTC](https://discuss.elastic.co/t/problem-with-timestamp/72561/2 "2017-01-24T06:53:39Z")

</div>

What does the input timestamp look like? What does the resulting event look like? What's in the Logstash logs (the date filter logs information about all parse failures)?

---

<div class="post-metadata">

**Author:** ![satishsnv](https://avatars.discourse-cdn.com/v4/letter/s/76d3ee/32.png) [@satishsnv](https://discuss.elastic.co/u/satishsnv)\
**Post date:** [January 24, 2017, 9:51am UTC](https://discuss.elastic.co/t/problem-with-timestamp/72561/3 "2017-01-24T09:51:31Z")

</div>

Hi magnus,

following is the output from logstash

{"ipaddress":"169.254.133.10","secEventType":"authentication","messageID":"messageID0","userName":"u  
serName0","Info":"Info0","tags":["\_dateparsefailure"],"timeStamp":"Tue 2017 Jan 24, 02:36:31:088","p  
ath":"C:/satish/SecurityEvent-2017-Jan-24.log","@timestamp":"2017-01-24T02:54:50.239Z","info1":"abc0  
","@version":"1","host":"L24660WIN","ID":"000891b7-1907-40ed-a1d5-d0a51be07ad3","info2":"xyz0"}

In the logstash config i have given the time format in the date filter, so as to convert it in to date type  
"timeStamp":"Tue 2017 Jan 24, 02:36:31:088" In GMT format(this is logevent time)  
"@timestamp":"2017-01-24T02:54:50.239Z"  
not matching my time format.

also i want to remove timestamp which is of string type, that is also not working.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 24, 2017, 10:08am UTC](https://discuss.elastic.co/t/problem-with-timestamp/72561/4 "2017-01-24T10:08:40Z")

</div>

What's in the Logstash logs (the date filter logs information about all parse failures)?

---

<div class="post-metadata">

**Author:** ![satishsnv](https://avatars.discourse-cdn.com/v4/letter/s/76d3ee/32.png) [@satishsnv](https://discuss.elastic.co/u/satishsnv)\
**Post date:** [January 24, 2017, 10:14am UTC](https://discuss.elastic.co/t/problem-with-timestamp/72561/5 "2017-01-24T10:14:02Z")

</div>

logstash log is same as posted in following thread

> [@Problem in converting string to ip](https://discuss.elastic.co/t/problem-in-converting-string-to-ip/72562):
>
> Hi i tried to convert string to ip by following the steps provided in the threads but its not working for me. I am getting following error on starting kibana. 08:24:50.444 [[main]-pipeline-manager] INFO logstash.outputs.elasticsearch - Installing elasticsear ch template to \_template/logstash 08:24:50.486 [[main]-pipeline-manager] ERROR logstash.outputs.elasticsearch - Failed to install temp late. {:message=\>"Got response code '400' contact Elasticsearch at URL '[http://localhost:9200/\_templ](http://localhost:9200/_templ) …

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 24, 2017, 10:16am UTC](https://discuss.elastic.co/t/problem-with-timestamp/72561/6 "2017-01-24T10:16:33Z")

</div>

> logstash log is same as posted in following thread

Okay, but that log doesn't contain anything from the date filter. I'm quite sure there's something in there. If you temporarily replace your elasticsearch output with `stdout { codec => rubydebug }` output this problem will be easier to debug.

---

<div class="post-metadata">

**Author:** ![satishsnv](https://avatars.discourse-cdn.com/v4/letter/s/76d3ee/32.png) [@satishsnv](https://discuss.elastic.co/u/satishsnv)\
**Post date:** [January 24, 2017, 10:32am UTC](https://discuss.elastic.co/t/problem-with-timestamp/72561/7 "2017-01-24T10:32:05Z")

</div>

Hi magnus,

i found the issue it is with the "," missed in the timeformat. This got fixed.  
i had another issue

my input log to logstash is  
{"ID":"c0306973-4c74-4cf0-9026-974b09dbab28","secEventType":"Authentication","timeStamp":"Tue 2017 Jan 24, 10:22:47:888","userName":"userName0","ipaddress":"169.254.133.10","Info":"Info0","messageID":"messageID0","info1":"abc0","info2":"xyz0"}

out put is  
{"ipaddress":"169.254.133.10","secEventType":"authentication","messageID":"messageID0","userName":"u  
serName0","Info":"Info0","path":"C:/satish/SecurityEvent-2017-Jan-24.log","@timestamp":"2017-01-24T0  
4:52:47.888Z","info1":"abc0","@version":"1","host":"L24660WIN","ID":"c0306973-4c74-4cf0-9026-974b09d  
bab28","info2":"xyz0"}

why the time format is not persisting? Also is it possible to keep timestamp(my field) and avoid creation of @timestamp(created by logstash)?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 24, 2017, 10:37am UTC](https://discuss.elastic.co/t/problem-with-timestamp/72561/8 "2017-01-24T10:37:34Z")

</div>

> why the time format is not persisting?

The purpose of the date filter is to parse a timestamp and store it in a field in a canonical format that's recognized by (for example) Elasticsearch. If you don't want to change the time format then you shouldn't use the date filter but then you'll instead have to arrange for Elasticsearch to do the parsing so that documents get the correct timestamp.

> Also is it possible to keep timestamp(my field) and avoid creation of @timestamp(created by logstash)?

Look at the filter's `target` option.

---

<div class="post-metadata">

**Author:** ![satishsnv](https://avatars.discourse-cdn.com/v4/letter/s/76d3ee/32.png) [@satishsnv](https://discuss.elastic.co/u/satishsnv)\
**Post date:** [January 24, 2017, 2:49pm UTC](https://discuss.elastic.co/t/problem-with-timestamp/72561/9 "2017-01-24T14:49:25Z")

</div>

thanks for the suggestion, it worked

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 21, 2017, 2:49pm UTC](https://discuss.elastic.co/t/problem-with-timestamp/72561/10 "2017-02-21T14:49:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
