# Remove Time Zone from Logstash output

**URL:** <https://discuss.elastic.co/t/remove-time-zone-from-logstash-output/71892>\
**Category:** Logstash\
**Created:** [January 17, 2017, 6:22pm UTC](https://discuss.elastic.co/t/remove-time-zone-from-logstash-output/71892 "2017-01-17T18:22:13Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rkhapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rkhapre/32/48333_2.png) [@rkhapre](https://discuss.elastic.co/u/rkhapre)\
**Post date:** [January 17, 2017, 6:22pm UTC](https://discuss.elastic.co/t/remove-time-zone-from-logstash-output/71892/1 "2017-01-17T18:22:13Z")

</div>

I am trying following to remove the 'Z' from logstash output but its not working

Do we have any working solution here

In my source the date format is is `yyyy-MM-dd HH:mm:ss.SSS`

the Actual output i am getting from logstash is `yyyy-MM-ddTHH:mm:ss.SSSZ`

Expected result is `yyyy-MM-ddTHH:mm:ss.SSS` or `yyyy-MM-ddTHH:mm:ss.SSS-08:00`

I am trying this below filter, but no luck

```
date {
  match => ["eventdate" , "yyyy-MM-ddTHH:mm:ss.SSS-08:00"]
  timezone => "UTC"
}

```

Please help out here

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 17, 2017, 6:59pm UTC](https://discuss.elastic.co/t/remove-time-zone-from-logstash-output/71892/2 "2017-01-17T18:59:29Z")

</div>

What output(s) are you using?

---

<div class="post-metadata">

**Author:** ![rkhapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rkhapre/32/48333_2.png) [@rkhapre](https://discuss.elastic.co/u/rkhapre)\
**Post date:** [January 18, 2017, 4:32am UTC](https://discuss.elastic.co/t/remove-time-zone-from-logstash-output/71892/3 "2017-01-18T04:32:32Z")

</div>

Hi @magnusbaeck

I am using http output a REST API and my input is jdbc

Thanks!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 18, 2017, 6:29am UTC](https://discuss.elastic.co/t/remove-time-zone-from-logstash-output/71892/4 "2017-01-18T06:29:14Z")

</div>

Okay. I think the REST endpoint should be capable of parsing just about any ISO8601 timestamp, but maybe it's not under your control. You'll have to use a ruby filter to format the timestamp value in the format you prefer and save it in a field that you can reference in your http output. I'm afraid I don't have any example code for this.

---

<div class="post-metadata">

**Author:** ![rkhapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rkhapre/32/48333_2.png) [@rkhapre](https://discuss.elastic.co/u/rkhapre)\
**Post date:** [January 18, 2017, 7:15am UTC](https://discuss.elastic.co/t/remove-time-zone-from-logstash-output/71892/5 "2017-01-18T07:15:43Z")

</div>

I am okay if we can get this `yyyy-MM-ddTHH:mm:ss.SS`S in text/string format also.

Not necessarily to have in date format

can we use some grok or gsub.?

Is there any way to convert date to a text and then use gsub?

I tried those but i have never used these plugin, so not getting any output

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 15, 2017, 7:15am UTC](https://discuss.elastic.co/t/remove-time-zone-from-logstash-output/71892/6 "2017-02-15T07:15:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
