# Replace @timestamp to time from actual log file

**URL:** <https://discuss.elastic.co/t/replace-timestamp-to-time-from-actual-log-file/236330>\
**Category:** Logstash\
**Created:** [June 9, 2020, 12:19pm UTC](https://discuss.elastic.co/t/replace-timestamp-to-time-from-actual-log-file/236330 "2020-06-09T12:19:47Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Youssef\_SBAI](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/youssef_sbai/32/64242_2.png) [@Youssef\_SBAI](https://discuss.elastic.co/u/Youssef_SBAI)\
**Post date:** [June 9, 2020, 12:19pm UTC](https://discuss.elastic.co/t/replace-timestamp-to-time-from-actual-log-file/236330/1 "2020-06-09T12:19:48Z")

</div>

Hello it is possible to Change @timestamp to time from actual log file

I use this config

```auto
filter {
  date {
    match => ["timestamp", "ISO8601"]
  }
}

```

But it does not work

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 9, 2020, 1:00pm UTC](https://discuss.elastic.co/t/replace-timestamp-to-time-from-actual-log-file/236330/2 "2020-06-09T13:00:41Z")

</div>

What does not work?  
Could you give a concrete example of the event before and after?

---

<div class="post-metadata">

**Author:** ![Youssef\_SBAI](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/youssef_sbai/32/64242_2.png) [@Youssef\_SBAI](https://discuss.elastic.co/u/Youssef_SBAI)\
**Post date:** [June 9, 2020, 1:04pm UTC](https://discuss.elastic.co/t/replace-timestamp-to-time-from-actual-log-file/236330/3 "2020-06-09T13:04:24Z")

</div>

My index names is logstash-2020.06.09 but the @timestamp is

![image](https://us1.discourse-cdn.com/elastic/original/3X/9/0/90e5b602c13b050148e96dc1138342f3133ac1a7.png)

---

<div class="post-metadata">

**Author:** ![Youssef\_SBAI](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/youssef_sbai/32/64242_2.png) [@Youssef\_SBAI](https://discuss.elastic.co/u/Youssef_SBAI)\
**Post date:** [June 9, 2020, 1:05pm UTC](https://discuss.elastic.co/t/replace-timestamp-to-time-from-actual-log-file/236330/4 "2020-06-09T13:05:45Z")

</div>

logstash not parsing `@timestamp` correctly, it is possible to change `@timestamp` to time from actual log file

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [June 9, 2020, 1:29pm UTC](https://discuss.elastic.co/t/replace-timestamp-to-time-from-actual-log-file/236330/5 "2020-06-09T13:29:03Z")

</div>

Most of the people who might try to help you are not psychic. If you complain about the wrong output, you need to give us your input. If you cannot solve your problem while having all the information, you cannot expect us to solve it with only the half of it.

---

<div class="post-metadata">

**Author:** ![Youssef\_SBAI](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/youssef_sbai/32/64242_2.png) [@Youssef\_SBAI](https://discuss.elastic.co/u/Youssef_SBAI)\
**Post date:** [June 9, 2020, 1:32pm UTC](https://discuss.elastic.co/t/replace-timestamp-to-time-from-actual-log-file/236330/6 "2020-06-09T13:32:43Z")

</div>

my config logstash is

```
input {
beats {
port => "5044"
}
}  

filter {

csv {
separator => ","
columns => ["chaine", "job", "date_plan", "statut", "date_debut", "date_fin", "serveur", "numero_passage", "application", "sous_application"]
skip_header => "true"
}

date {
match => ["timestamp", "YYYY-MM-dd;HH:mm:ss.SSS"]
target => "@timestamp"
}

date {
match => ["date_plan" , "YYYY-MM-dd"]
timezone => "Europe/Paris"
}

date {
match => ["date_debut" , "YYYY-MM-dd HH:mm:ss"]
timezone => "Europe/Paris"
}

date {
match => ["date_fin" , "YYYY-MM-dd HH:mm:ss"]
timezone => "Europe/Paris"
}

mutate {
convert => { "numero_passage" => "integer" }
}
}

output {
elasticsearch {
hosts => ["http://elasticsearch:9200"]
index => "<logstash-{now/d}>"

}
stdout {
   codec => rubydebug
}
}
```

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [June 9, 2020, 1:39pm UTC](https://discuss.elastic.co/t/replace-timestamp-to-time-from-actual-log-file/236330/7 "2020-06-09T13:39:11Z")

</div>

I hope you realize that this configuration would overwrite `@timestamp` again and again and again … That field is the default target of the date filter.

---

<div class="post-metadata">

**Author:** ![Youssef\_SBAI](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/youssef_sbai/32/64242_2.png) [@Youssef\_SBAI](https://discuss.elastic.co/u/Youssef_SBAI)\
**Post date:** [June 9, 2020, 1:43pm UTC](https://discuss.elastic.co/t/replace-timestamp-to-time-from-actual-log-file/236330/8 "2020-06-09T13:43:48Z")

</div>

I know but `@timestamp`s is not parsing correctly with today's date

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [June 9, 2020, 1:47pm UTC](https://discuss.elastic.co/t/replace-timestamp-to-time-from-actual-log-file/236330/9 "2020-06-09T13:47:06Z")

</div>

I just meant to say that, even if it would parse the date correctly, the value wouldn't be kept. (And you still haven't posted your input.)

---

<div class="post-metadata">

**Author:** ![Youssef\_SBAI](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/youssef_sbai/32/64242_2.png) [@Youssef\_SBAI](https://discuss.elastic.co/u/Youssef_SBAI)\
**Post date:** [June 9, 2020, 1:49pm UTC](https://discuss.elastic.co/t/replace-timestamp-to-time-from-actual-log-file/236330/10 "2020-06-09T13:49:53Z")

</div>

my config filebeat is

```
filebeat.inputs:
- type: log
  enabled: true
  paths:  
     - /data/volumes/monitoring/logstash/logCtrlM/poc_prode.csv

exclude_lines: ['^chaine']

output.logstash:
  hosts: ["logstash:5044"]
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 9, 2020, 1:53pm UTC](https://discuss.elastic.co/t/replace-timestamp-to-time-from-actual-log-file/236330/11 "2020-06-09T13:53:05Z")

</div>

Could you please indent your code correctly to make it easier to read?  
Also post the first lines of your CSV file.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 9, 2020, 2:02pm UTC](https://discuss.elastic.co/t/replace-timestamp-to-time-from-actual-log-file/236330/12 "2020-06-09T14:02:56Z")

</div>

Adding to @Jenni's answer the link to the documentation. [Date filter plugin | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html#plugins-filters-date-target)

It says:

> Store the matching timestamp into the given target field. If not provided, default to updating the `@timestamp` field of the event.

Which means that `date_fin` will at the end overwrite any other parsed values for `@timestamp` field.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 7, 2020, 2:03pm UTC](https://discuss.elastic.co/t/replace-timestamp-to-time-from-actual-log-file/236330/13 "2020-07-07T14:03:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
