# Reading Epoch As @timestamp

**URL:** <https://discuss.elastic.co/t/reading-epoch-as-timestamp/20361>\
**Category:** Elasticsearch\
**Created:** [October 21, 2014, 11:43am UTC](https://discuss.elastic.co/t/reading-epoch-as-timestamp/20361 "2014-10-21T11:43:08Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ES\_USER1](https://avatars.discourse-cdn.com/v4/letter/e/74df32/32.png) [@ES\_USER1](https://discuss.elastic.co/u/ES_USER1)\
**Post date:** [October 21, 2014, 11:43am UTC](https://discuss.elastic.co/t/reading-epoch-as-timestamp/20361/1 "2014-10-21T11:43:08Z")

</div>

For the life of me my Google searching has not revealed any solution to  
this at least none that work for me. I have log data with an Epoch  
timestamp in it and would like to use the date filter in Logstash to  
overwrite @timestamp with the appropriate converted timestamp derived from  
that epoch. Any insight on this would be much appreciated.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/4bd3b3d1-ed8f-4212-92dc-4c7496d7c88d%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4bd3b3d1-ed8f-4212-92dc-4c7496d7c88d%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![vineeth\_mohan\_2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vineeth_mohan_2/32/747_2.png) [@vineeth\_mohan\_2](https://discuss.elastic.co/u/vineeth_mohan_2)\
**Post date:** [October 21, 2014, 12:12pm UTC](https://discuss.elastic.co/t/reading-epoch-as-timestamp/20361/2 "2014-10-21T12:12:17Z")

</div>

Hi ,

What exactly do you mean by "overwrite @timestamp".  
It would be also helpful if you can quite an example.

Thanks  
Vineeth

On Tue, Oct 21, 2014 at 5:13 PM, ES USER [es.user.2014@gmail.com](mailto:es.user.2014@gmail.com) wrote:

> For the life of me my Google searching has not revealed any solution to  
> this at least none that work for me. I have log data with an Epoch  
> timestamp in it and would like to use the date filter in Logstash to  
> overwrite @timestamp with the appropriate converted timestamp derived from  
> that epoch. Any insight on this would be much appreciated.
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/4bd3b3d1-ed8f-4212-92dc-4c7496d7c88d%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4bd3b3d1-ed8f-4212-92dc-4c7496d7c88d%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/4bd3b3d1-ed8f-4212-92dc-4c7496d7c88d%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/4bd3b3d1-ed8f-4212-92dc-4c7496d7c88d%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAGdPd5nPPWmb6FA8y60vrYXR2%3D8B-NJOf\_k\_ZUEdGyOuUYV1gQ%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAGdPd5nPPWmb6FA8y60vrYXR2%3D8B-NJOf_k_ZUEdGyOuUYV1gQ%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Antonio\_Augusto\_Sant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/antonio_augusto_sant/32/82851_2.png) [@Antonio\_Augusto\_Sant](https://discuss.elastic.co/u/Antonio_Augusto_Sant)\
**Post date:** [October 21, 2014, 2:08pm UTC](https://discuss.elastic.co/t/reading-epoch-as-timestamp/20361/3 "2014-10-21T14:08:01Z")

</div>

If you are using logstash to push your events do ES you need something like  
this:

date {  
match =\> ["\<field\_with\_the\_epoch\>", "UNIX"]  
}

Read more about it here: [Date filter plugin | Logstash Reference [8.11] | Elastic](http://logstash.net/docs/1.4.2/filters/date)

On Tuesday, October 21, 2014 8:43:08 AM UTC-3, ES USER wrote:

> For the life of me my Google searching has not revealed any solution to  
> this at least none that work for me. I have log data with an Epoch  
> timestamp in it and would like to use the date filter in Logstash to  
> overwrite @timestamp with the appropriate converted timestamp derived from  
> that epoch. Any insight on this would be much appreciated.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/ee39dee4-b113-4fcf-80d6-4d4e7063afc9%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ee39dee4-b113-4fcf-80d6-4d4e7063afc9%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![vineeth\_mohan\_2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vineeth_mohan_2/32/747_2.png) [@vineeth\_mohan\_2](https://discuss.elastic.co/u/vineeth_mohan_2)\
**Post date:** [October 22, 2014, 5:08am UTC](https://discuss.elastic.co/t/reading-epoch-as-timestamp/20361/4 "2014-10-22T05:08:22Z")

</div>

Hello Antonio ,

I am aware of this.  
The example you have quoted should actually work.  
Why do you feel that its not working.

Thanks  
Vineeth

On Tue, Oct 21, 2014 at 7:38 PM, Antonio Augusto Santos [mkhaos7@gmail.com](mailto:mkhaos7@gmail.com)  
wrote:

> If you are using logstash to push your events do ES you need something  
> like this:
> 
> date {  
> match =\> ["\<field\_with\_the\_epoch\>", "UNIX"]  
> }
> 
> Read more about it here: [Date filter plugin | Logstash Reference [8.11] | Elastic](http://logstash.net/docs/1.4.2/filters/date)
> 
> On Tuesday, October 21, 2014 8:43:08 AM UTC-3, ES USER wrote:
> 
> > For the life of me my Google searching has not revealed any solution to  
> > this at least none that work for me. I have log data with an Epoch  
> > timestamp in it and would like to use the date filter in Logstash to  
> > overwrite @timestamp with the appropriate converted timestamp derived from  
> > that epoch. Any insight on this would be much appreciated.
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/ee39dee4-b113-4fcf-80d6-4d4e7063afc9%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ee39dee4-b113-4fcf-80d6-4d4e7063afc9%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/ee39dee4-b113-4fcf-80d6-4d4e7063afc9%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/ee39dee4-b113-4fcf-80d6-4d4e7063afc9%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .
> 
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAGdPd5krBWRsCEmEENm0O4oA6SCwUukzTrdQsTnbXbDNVcv1ow%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAGdPd5krBWRsCEmEENm0O4oA6SCwUukzTrdQsTnbXbDNVcv1ow%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![ES\_USER1](https://avatars.discourse-cdn.com/v4/letter/e/74df32/32.png) [@ES\_USER1](https://discuss.elastic.co/u/ES_USER1)\
**Post date:** [October 22, 2014, 2:25pm UTC](https://discuss.elastic.co/t/reading-epoch-as-timestamp/20361/5 "2014-10-22T14:25:40Z")

</div>

Antonio's example works. My problem was a syntax issue as the Logstash  
docs do not really have examples. I was not able to figure out the  
formatting.

On Wednesday, October 22, 2014 1:08:33 AM UTC-4, vineeth mohan wrote:

> Hello Antonio ,
> 
> I am aware of this.  
> The example you have quoted should actually work.  
> Why do you feel that its not working.
> 
> Thanks  
> Vineeth
> 
> On Tue, Oct 21, 2014 at 7:38 PM, Antonio Augusto Santos \<[mkh...@gmail.com](mailto:mkh...@gmail.com)  
> \<javascript:\>\> wrote:
> 
> > If you are using logstash to push your events do ES you need something  
> > like this:
> > 
> > date {  
> > match =\> ["\<field\_with\_the\_epoch\>", "UNIX"]  
> > }
> > 
> > Read more about it here: [Date filter plugin | Logstash Reference [8.11] | Elastic](http://logstash.net/docs/1.4.2/filters/date)
> > 
> > On Tuesday, October 21, 2014 8:43:08 AM UTC-3, ES USER wrote:
> > 
> > > For the life of me my Google searching has not revealed any solution to  
> > > this at least none that work for me. I have log data with an Epoch  
> > > timestamp in it and would like to use the date filter in Logstash to  
> > > overwrite @timestamp with the appropriate converted timestamp derived from  
> > > that epoch. Any insight on this would be much appreciated.
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/ee39dee4-b113-4fcf-80d6-4d4e7063afc9%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ee39dee4-b113-4fcf-80d6-4d4e7063afc9%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/ee39dee4-b113-4fcf-80d6-4d4e7063afc9%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/ee39dee4-b113-4fcf-80d6-4d4e7063afc9%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .
> > 
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/cfd1699c-f41d-4501-a931-8887a9bbb585%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/cfd1699c-f41d-4501-a931-8887a9bbb585%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:54am UTC](https://discuss.elastic.co/t/reading-epoch-as-timestamp/20361/6 "2017-07-06T00:54:25Z")

</div>


