# Replacement @timestamp stop show any result in Kibana with enabled time filter

**URL:** <https://discuss.elastic.co/t/replacement-timestamp-stop-show-any-result-in-kibana-with-enabled-time-filter/103131>\
**Category:** Logstash\
**Created:** [October 8, 2017, 12:57am UTC](https://discuss.elastic.co/t/replacement-timestamp-stop-show-any-result-in-kibana-with-enabled-time-filter/103131 "2017-10-08T00:57:45Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![artcont](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/artcont/32/22859_2.png) [@artcont](https://discuss.elastic.co/u/artcont)\
**Post date:** [October 8, 2017, 12:57am UTC](https://discuss.elastic.co/t/replacement-timestamp-stop-show-any-result-in-kibana-with-enabled-time-filter/103131/1 "2017-10-08T00:57:46Z")

</div>

Hello, i have issue with settings up Kibana and Logstash.  
What actually happens.

1. I setup filter date in logstash for replace @timeshtamp with my actual time from log.
2. I configure an index pattern in Kibana with "Time Filter field name" =\> @timestamp  
After this steps, "Discover page" in Kibana show me empty page (not blank) just "No results found" message (

If i remove date replacement for system field @timestamp. All work fine (

Using Dev Tools i see that @timestamp field writed correct (with my log date / time).

My filter config is:

> if "api.log" in [source] {  
> grok {  
> patterns\_dir =\> ["/etc/logstash/patterns"]  
> match =\> { "message" =\> "%{BASELOG}" }  
> }  
> date {  
> match =\> ["timestamp", "yyyy-MM-dd HH:mm:ss,SSS"]  
> target =\> "@timestamp"  
> remove\_field =\> ["timestamp"]  
> }  
> mutate {  
> replace =\> { "type" =\> "api" }  
> replace =\> { "message" =\> "%{msg}" }  
> remove\_field =\> ["msg"]  
> }  
> }

my custom\_patterns:  
JAVATIMESTAMP %{YEAR}-%{MONTHNUM}-%{MONTHDAY} %{HOUR}:?%{MINUTE}(?::?%{SECOND})  
JAVALOGHEADER %{JAVATIMESTAMP:timestamp} %{LOGLEVEL:level} [%{JAVACLASS:class}]  
BASELOG %{JAVALOGHEADER} - %{GREEDYDATA:msg}

one of ES records:

```
  {
    "_index": "logstash-2017.10.08",
    "_type": "api",
    "_id": "AV75Y5a1xVCz_fS_LhpO",
    "_score": 1,
    "_source": {
      "hostname": "hidden",
      "@timestamp": "2017-10-08T03:30:03.692Z",
      "level": "TRACE",
      "source": "/some/source/logs/hidden.log",
      "message": "Some message: Some extra message",
      "type": "api",
      "class": "com.some.awesome.class.of.java"
    }
  }

```

Can some one explain me, what I'm doing wrong?  
Many thanks for helping!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 5, 2017, 12:57am UTC](https://discuss.elastic.co/t/replacement-timestamp-stop-show-any-result-in-kibana-with-enabled-time-filter/103131/2 "2017-11-05T00:57:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
