# Query @timestamp return epoch time

**URL:** <https://discuss.elastic.co/t/query-timestamp-return-epoch-time/87796>\
**Category:** Elasticsearch\
**Created:** [May 31, 2017, 7:33pm UTC](https://discuss.elastic.co/t/query-timestamp-return-epoch-time/87796 "2017-05-31T19:33:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mdidomenico](https://avatars.discourse-cdn.com/v4/letter/m/c4cdca/32.png) [@mdidomenico](https://discuss.elastic.co/u/mdidomenico)\
**Post date:** [May 31, 2017, 7:33pm UTC](https://discuss.elastic.co/t/query-timestamp-return-epoch-time/87796/1 "2017-05-31T19:33:10Z")

</div>

When i query elasticsearch the @timestamp field comes back at iso8601 format. is there a way to get the field back as epoch time instead? the @timestamp field in my index is the regular 'date' field for elastic search.

everything works fine for querying with date ranges and such, but i'd like to work on the data in a program that uses epoch time instead of iso8601.

i can convert iso8601 to epoch time in perl, but it's way slow using the DateTime module. it would be nicer if elasticsearch would just return the epoch time in the field instead of iso8601

---

<div class="post-metadata">

**Author:** ![Mike.Barretta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike.barretta/32/16688_2.png) [@Mike.Barretta](https://discuss.elastic.co/u/Mike.Barretta)\
**Post date:** [June 1, 2017, 3:05pm UTC](https://discuss.elastic.co/t/query-timestamp-return-epoch-time/87796/2 "2017-06-01T15:05:42Z")

</div>

Interestingly, Elasticsearch stores its dates as epoch milliseconds unless you explicitly disable doc\_values for that field, so it's not too difficult to fetch it as such.

Two suggestions:

1. index both forms of the date (e.g. "date\_iso8601" and "date\_epoch") so that you can use whichever is most convenient for a given operation
2. pull the underlying docvalue value:

```auto
PUT my_index
{
  "mappings": {
    "my_type": {
      "properties": {
        "date": {
          "type": "date",
          "format": "date_time_no_millis"
        }
      }
    }
  }
}

PUT my_index/my_type/1
{
  "date": "2017-01-01T12:00:00-05:00" 
} 

GET my_index/_search 
{
  "query":{
    "match_all": {}
  }, 
  "docvalue_fields": ["date"]
}

```

---

<div class="post-metadata">

**Author:** ![mdidomenico](https://avatars.discourse-cdn.com/v4/letter/m/c4cdca/32.png) [@mdidomenico](https://discuss.elastic.co/u/mdidomenico)\
**Post date:** [June 2, 2017, 1:59pm UTC](https://discuss.elastic.co/t/query-timestamp-return-epoch-time/87796/3 "2017-06-02T13:59:58Z")

</div>

Thanks. I ended up just putting the time in both formats into the index, one as a long and the other as date. i'll look at docvalue\_fields for the next project. i was hopeful since the date was already in epoch time, i could just get the date in epoch or some other format as part of the display of the data rather then add more data to the index. but i image its more complicated under the covers then that.

---

<div class="post-metadata">

**Author:** ![Mike.Barretta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike.barretta/32/16688_2.png) [@Mike.Barretta](https://discuss.elastic.co/u/Mike.Barretta)\
**Post date:** [June 5, 2017, 9:31pm UTC](https://discuss.elastic.co/t/query-timestamp-return-epoch-time/87796/4 "2017-06-05T21:31:11Z")

</div>

> [@mdidomenico](#):
>
> i was hopeful since the date was already in epoch time, i could just get the date in epoch or some other format as part of the display of the data rather then add more data to the index. but i image its more complicated under the covers then that.

That #2 option I proposed was indeed a way to get the underlying epoch time out without having to store two copies of the date. That said, it does seem a bit clunky and also doesn't work as part of the Document API (`GET /{index}/{type}/{id}`). Considering the optimizations around storing and retrieving longs, I think the extra flexibility gained with the duplication is probably worth it, but you'd be the best to judge!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2017, 9:31pm UTC](https://discuss.elastic.co/t/query-timestamp-return-epoch-time/87796/5 "2017-07-03T21:31:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
