# Removing string from this form of time stamp

**URL:** https://discuss.elastic.co/t/removing-string-from-this-form-of-time-stamp/55838
**Category:** Logstash
**Created:** [July 19, 2016, 7:52am UTC](https://discuss.elastic.co/t/removing-string-from-this-form-of-time-stamp/55838 "2016-07-19T07:52:30Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![jihoon](https://avatars.discourse-cdn.com/v4/letter/j/f14d63/32.png) [@jihoon](https://discuss.elastic.co/u/jihoon)
#### Post date: [July 19, 2016, 7:52am UTC](https://discuss.elastic.co/t/removing-string-from-this-form-of-time-stamp/55838/1 "2016-07-19T07:52:30Z")

</div>

This process had the following timestamp.

"2016-07-19 16:02:17"  
filter {  
date {  
match =\> ["message", "YYYY-MM-dd HH:mm:ss", "ISO8601"]  
target =\> "abctime"  
}  
}

But these have to do with the time stamp?  
"2016-07-19 AM 11:04:19"  
"2016-07-19 PM 16:02:17"

You can remove the string(AM or PM) and specify a timestamp?

Answers please. thank you.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [July 19, 2016, 10:02am UTC](https://discuss.elastic.co/t/removing-string-from-this-form-of-time-stamp/55838/2 "2016-07-19T10:02:20Z")

</div>

You could use the mutate filter's gsub option to replace the pattern " (AM|PM) " with an empty string.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 4:47am UTC](https://discuss.elastic.co/t/removing-string-from-this-form-of-time-stamp/55838/3 "2017-07-06T04:47:28Z")

</div>


