# Query on @timestamp mapping

**URL:** <https://discuss.elastic.co/t/query-on-timestamp-mapping/59870>\
**Category:** Elasticsearch\
**Created:** [September 6, 2016, 10:29am UTC](https://discuss.elastic.co/t/query-on-timestamp-mapping/59870 "2016-09-06T10:29:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sharath3185](https://avatars.discourse-cdn.com/v4/letter/s/2bfe46/32.png) [@sharath3185](https://discuss.elastic.co/u/sharath3185)\
**Post date:** [September 6, 2016, 10:29am UTC](https://discuss.elastic.co/t/query-on-timestamp-mapping/59870/1 "2016-09-06T10:29:45Z")

</div>

Hi,  
I have a logstash config file which parses some logs and indexes them into elasticsearch.  
I have renamed the @timestamp field to "timestamp" field for my convenience in my project as below

mutate  
{  
rename =\> { "@timestamp" =\> "timestamp" }  
}

I have not specified any mapping for the above timestamp field in elasticsearch, so elasticsearch takes the default mapping as:

"timestamp" : {  
"type" : "date",  
"format" : "strict\_date\_optional\_time||epoch\_millis"  
}

But now I want to change the format of timestamp to "yyyy-MM-dd HH:mm:ss" or "MMM dd yyyy HH:MM:SS"

If I try the above mappings in my mapping, and tries to parse the file through logstash, it throws the below error:

**"reason"=\>"Failed to parse mapping [testinfo]: Root mapping definition has unsupported parameters: [timestamp : {format=YYYY-MM-dd:HH:mm:ss||epoch\_millis, type=date}]", "caused\_by"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"Root mapping definition has unsupported parameters: [timestamp : {format=YYYY-MM-dd HH:mm:ss||epoch\_millis, type=date}]"}}}}, :level=\>:warn}**

Could you please let me know how to overcome this issue?

---

<div class="post-metadata">

**Author:** ![tanguy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tanguy/32/6030_2.png) [@tanguy](https://discuss.elastic.co/u/tanguy)\
**Post date:** [September 6, 2016, 10:51am UTC](https://discuss.elastic.co/t/query-on-timestamp-mapping/59870/2 "2016-09-06T10:51:31Z")

</div>

Hi,

There's something wrong in your mapping. Can you please copy/paste your mapping update request here?

---

<div class="post-metadata">

**Author:** ![sharath3185](https://avatars.discourse-cdn.com/v4/letter/s/2bfe46/32.png) [@sharath3185](https://discuss.elastic.co/u/sharath3185)\
**Post date:** [September 6, 2016, 12:12pm UTC](https://discuss.elastic.co/t/query-on-timestamp-mapping/59870/3 "2016-09-06T12:12:23Z")

</div>

mapping:

"mappings": {  
"testinfo": {  
"dynamic\_templates": [{  
"string\_fields": {  
"match": "\*",  
"match\_mapping\_type": "string",  
"mapping": {  
"type": "string",  
"analyzer": "whitespaceanalyzer",  
"fields": {  
"raw": {  
"type": "string",  
"index": "not\_analyzed"  
}  
}  
}

```
			}
		}],
		"properties": {
		 "timestamp" : {
        "type" : "date",
        "format" : "YYYY-mm-dd HH:mm:ss||epoch_millis"
      }}
	}

```

}

Config file:

input  
{  
file  
{  
codec =\> multiline  
{  
pattern =\> 'Logfile is saved'  
negate =\> true  
what =\> previous  
}  
path =\> ["path/to/log"]  
start\_position =\> "beginning"  
#sincedb\_path =\> "/path/to/NSP.db1"  
sincedb\_path =\> "/dev/null"  
type =\> "NSP"  
ignore\_older =\> 0

```
}

```

}

filter  
{  
if [type] == "NSP"  
{  
ruby  
{  
code =\> "  
filename = event['path'].split('/')[-5];  
event['job'] = filename  
stagename\_temp = event['path'].split('/')[-3];  
stagename = stagename\_temp.split('\_\_').last;  
event['stage'] = stagename+'\_'+event['job']  
event['logpath']= event['path'].strip  
"  
}  
grok  
{  
match =\> [  
"message" , "%{GREEDYDATA}INFO-\> Test Script Name: %{GREEDYDATA:testname}\n%{YEAR}/%{MONTHNUM}/%{MONTHDAY}[T]%{HOUR}:?%{MINUTE}(?::?%{SECOND})?%{ISO8601\_TIMEZONE}? INFO-\> Logfile is %{GREEDYDATA:testlogpath}\n%{YEAR}/%{MONTHNUM}/%{MONTHDAY}[T]%{HOUR}:?%{MINUTE}(?::?%{SECOND})?%{ISO8601\_TIMEZONE}? INFO-\> Test Start time : %{GREEDYDATA:data3} INFO-\> The Script took %{GREEDYDATA:executiontime}\n%{YEAR}/%{MONTHNUM}/%{MONTHDAY}[T]%{HOUR}:?%{MINUTE}(?::?%{SECOND})?%{ISO8601\_TIMEZONE}?%{GREEDYDATA} Test Result: %{GREEDYDATA:status}"  
]  
}  
mutate  
{  
gsub =\> ["msg", "\r\n", ""]  
}  
if "\_jsonparsefailure" in [tags]  
{  
drop{}  
}

```
    if "_grokparsefailure" in [tags] 
    {
        drop {}
    }
    else 
    {
        mutate
        {
            rename => { "@timestamp" => "timestamp" }
            remove_field => ["message", "@version", "path", "host", data3, tags, "testlogpath"]
        }
    }
    if [status] == "Passed" 
    {	
        mutate 
        {
            replace => ["status", "pass"]
        }
    }
    else if [status] == "Failed" 
    {	
        mutate 
        {
            replace => ["status", "fail"]
        }
    }
    else if [status] == "Abort "
    {
        mutate 
        {
            replace => ["status", "abort"]
        }
    }
    else if [status] == "Abort"
    {
        mutate 
        {
            replace => ["status", "abort"]
        }
    }
    if "Hours" in [executiontime] 
    {
        mutate 
        {
            gsub => ["executiontime","Hours",""]
            gsub => ["executiontime","Minutes",""]
            gsub => ["executiontime","Seconds",""]
            gsub => ["executiontime"," ",""]
        }
    }
	ruby 
    {
        code => "
        hour = event['executiontime'].split(':')[0];
		min = event['executiontime'].split(':')[1];
		sec = event['executiontime'].split(':')[2];
        if(hour.length==1);
		    hour = '0'+hour;
		end;
		if(min.length==1);
		    min = '0'+min;
		end;
		if(sec.length==1);
		    sec = '0'+sec;
		end;
		event['executiontime'] = hour+':'+min+':'+sec
        "
    }
    mutate{
        gsub => ['executiontime', '^', '0d ']
    }
}

```

}

output  
{  
if [type] == "NSP"  
{  
stdout { codec =\> rubydebug }  
elasticsearch  
{  
template\_name =\> "my\_template"  
manage\_template =\> true  
template =\> "/etc/logstash/mapping/my\_template.json"  
hosts =\> "127.0.0.1:9200"  
index =\> "myindex"  
document\_type =\> "testinfo"  
document\_id =\> "%{job}\_%{testname}"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![sharath3185](https://avatars.discourse-cdn.com/v4/letter/s/2bfe46/32.png) [@sharath3185](https://discuss.elastic.co/u/sharath3185)\
**Post date:** [September 6, 2016, 12:31pm UTC](https://discuss.elastic.co/t/query-on-timestamp-mapping/59870/4 "2016-09-06T12:31:26Z")

</div>

I am placing my mapping into a template file and then use the template in my logstash config file so that the mapping gets applied.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:22pm UTC](https://discuss.elastic.co/t/query-on-timestamp-mapping/59870/5 "2017-07-05T22:22:19Z")

</div>


