# Return (emit) @timestamp date value in runtime field

**URL:** <https://discuss.elastic.co/t/return-emit-timestamp-date-value-in-runtime-field/311001>\
**Category:** Kibana\
**Tags:** runtime-fields\
**Created:** [July 29, 2022, 4:08pm UTC](https://discuss.elastic.co/t/return-emit-timestamp-date-value-in-runtime-field/311001 "2022-07-29T16:08:29Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![nilei](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nilei/32/90186_2.png) [@nilei](https://discuss.elastic.co/u/nilei)\
**Post date:** [July 29, 2022, 4:08pm UTC](https://discuss.elastic.co/t/return-emit-timestamp-date-value-in-runtime-field/311001/1 "2022-07-29T16:08:29Z")

</div>

Dear all,

I am trying to output the value of `@timestamp` in a runtime field (configured in Kibana 7.13.3). My goal is then to get only the month as display value with a modified format `'MMM'`. Unfortunately, I have been unsuccessful so far with all possible combinations that can be found on Google. I have not even managed to output the "normal" value of `@timestamp` or any other date field in a new runtime field.

```auto
emit(doc['@timestamp'].value);
                      ^---- HERE

```

In Discover, I then get this error message:

```auto
cannot convert MethodHandle(Dates)JodaCompatibleZonedDateTime to (Object)long

```

I also tried a gazillion of other things... with no success.

The same works great with a keyword field if I am using this:

```auto
emit(doc['user_name'].value);

```

How the heck does that work with dates 🙂 ???

Thanks a lot for your help!!!

-- Cheers, Nils

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 30, 2022, 4:22am UTC](https://discuss.elastic.co/t/return-emit-timestamp-date-value-in-runtime-field/311001/2 "2022-07-30T04:22:35Z")

</div>

```auto
emit(doc['@timestamp'].value.toString())
2022-07-23T22:31:10.171Z

emit(doc['@timestamp'].value.month.getDisplayName(TextStyle.FULL, Locale.ROOT))
July

emit(doc['@timestamp'].value.month.getDisplayName(TextStyle.SHORT, Locale.ROOT));
Jul

ZonedDateTime zdt = ZonedDateTime.parse(doc['@timestamp'].value.toString());
emit(zdt.getMonthValue());
7 (integer)

ZonedDateTime zdt = ZonedDateTime.parse(doc['@timestamp'].value.toString());
emit(zdt.getMonthValue().toString());
7 (keyword)

emit(doc['@timestamp'].value.dayOfWeekEnum.getDisplayName(TextStyle.FULL, Locale.ROOT))
Saturday

```

> **[Use Painless scripts in runtime fields | Painless Scripting Language \[master\]...](https://www.elastic.co/guide/en/elasticsearch/painless/master/painless-runtime-fields.html)**

> **[Using Datetime in Painless | Painless Scripting Language \[master\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/painless/master/painless-datetime.html)**

> **[Shared API for package java.time | Painless Scripting Language \[master\] |...](https://www.elastic.co/guide/en/elasticsearch/painless/master/painless-api-reference-shared-java-time.html#painless-api-reference-shared-ZonedDateTime)**

---

<div class="post-metadata">

**Author:** ![nilei](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nilei/32/90186_2.png) [@nilei](https://discuss.elastic.co/u/nilei)\
**Post date:** [July 30, 2022, 2:21pm UTC](https://discuss.elastic.co/t/return-emit-timestamp-date-value-in-runtime-field/311001/3 "2022-07-30T14:21:41Z")

</div>

Hey Stephen,

thanks a lot. This is a great resource of examples.

Could you help me further to return the value of `@timestamp` as a `Date` type in the runtime field? Using `.toString()`, which requires the runtime field to be a `Keyword` field, brings the problem that I cannot configure any custom date formatting, like `MMM`,

If I try to use `emit(doc['@timestamp'].value.toString())` and runtime field type `Date`, the Discover app shows an error:

`cannot convert MethodHandle(Object)String to (Object)long`

-- Cheers, Nils

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 30, 2022, 2:27pm UTC](https://discuss.elastic.co/t/return-emit-timestamp-date-value-in-runtime-field/311001/4 "2022-07-30T14:27:03Z")

</div>

Apologies I am Confused what you want then

`@timestamp` is already a `date`

` emit(doc['@timestamp'].value.toString())` is a string

Can you show me _ **exactly** _ what you want before and after and what data types you want before and after and how you plan to use the result and what type you want the result... I am lost / confused at this point.

---

<div class="post-metadata">

**Author:** ![nilei](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nilei/32/90186_2.png) [@nilei](https://discuss.elastic.co/u/nilei)\
**Post date:** [July 30, 2022, 2:33pm UTC](https://discuss.elastic.co/t/return-emit-timestamp-date-value-in-runtime-field/311001/5 "2022-07-30T14:33:59Z")

</div>

Hi Stephen,

thank you very much for your help!

I have data from about the last 10 years and would like an evaluation of which month has the most entries. As a date field I have the `@timestamp` field available. I need an evaluation of the data per month. Month should be for example "7" or "July". That would not matter. My plan was to create a runtime field, which gets the value of `@timestamp` and is displayed in the format `MMM`. So I still have the `@timestamp` field and additionally the month in a separate field.

-- Cheers, Nils

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 30, 2022, 2:38pm UTC](https://discuss.elastic.co/t/return-emit-timestamp-date-value-in-runtime-field/311001/6 "2022-07-30T14:38:52Z")

</div>

That is exactly what I showed you... confused... you have to name it as a new field..

You add a new field...this is in the Index Pattern if you which will work for visualizations.

 ![Screen Shot 2022-07-30 at 7.36.02 AM](https://us1.discourse-cdn.com/elastic/original/3X/3/b/3b872f4143b37075eaa310a8abd8be6cd73a4d4e.png)

BUT if you actually want to do searches / aggregation etc.. etc.. you need to add it to the mapping

```auto
PUT my-index-000001/
{
  "mappings": {
    "runtime": {
      "date_month_MMM": {
        "type": "keyword",
        "script": {
          "source": "emit(doc['@timestamp'].value.month.getDisplayName(TextStyle.SHORT, Locale.ROOT));"
        }
      }
    }

```

---

<div class="post-metadata">

**Author:** ![nilei](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nilei/32/90186_2.png) [@nilei](https://discuss.elastic.co/u/nilei)\
**Post date:** [July 30, 2022, 2:43pm UTC](https://discuss.elastic.co/t/return-emit-timestamp-date-value-in-runtime-field/311001/7 "2022-07-30T14:43:40Z")

</div>

Hi Stephen,

thanks for the clarification of the difference between `mapping` and `index pattern`. I am aware of this now. I also understand now how to return the month name as a string (`Keyword` runtime field), but I am still unsure how to return the value of `@timestamp` as a date (`Date` runtime field). Maybe I am just confused and the answer is too simple 🙂 Sorry if that is the case...

-- Cheers, Nils

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 30, 2022, 2:47pm UTC](https://discuss.elastic.co/t/return-emit-timestamp-date-value-in-runtime-field/311001/8 "2022-07-30T14:47:55Z")

</div>

`@timestamp` is already always available as a "indexed / concrete field" as a `date` type... why do you need it as a runtime field? @timestamp will always be available.

What do you mean the the value of `@timestamp` as a date (`Date` runtime field)

Can you show me what you mean? Are you just trying to format the date in a certain format?

Are you trying to build visualizations or DSL queries?

---

<div class="post-metadata">

**Author:** ![nilei](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nilei/32/90186_2.png) [@nilei](https://discuss.elastic.co/u/nilei)\
**Post date:** [July 30, 2022, 2:50pm UTC](https://discuss.elastic.co/t/return-emit-timestamp-date-value-in-runtime-field/311001/9 "2022-07-30T14:50:48Z")

</div>

Hi Stephen,

I want to show and use the Month and the Year in separate additional fields. My idea is to keep the fields as `Date` fields and just apply a custom formatting as needed.

-- Cheers, Nils

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 30, 2022, 2:53pm UTC](https://discuss.elastic.co/t/return-emit-timestamp-date-value-in-runtime-field/311001/10 "2022-07-30T14:53:36Z")

</div>

Ok just create another field with the Year part... you can create a field if you like for every part of the date if you like.

 ![Screen Shot 2022-07-30 at 7.56.22 AM](https://us1.discourse-cdn.com/elastic/original/3X/0/6/06b05191b10166146894d6da1effdea8d1350f2f.png)

---

<div class="post-metadata">

**Author:** ![nilei](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nilei/32/90186_2.png) [@nilei](https://discuss.elastic.co/u/nilei)\
**Post date:** [July 30, 2022, 2:57pm UTC](https://discuss.elastic.co/t/return-emit-timestamp-date-value-in-runtime-field/311001/11 "2022-07-30T14:57:33Z")

</div>

Hi Stephen,

let us just assume that I want to duplicate the `@timestamp` field into a runtime field. Let us call this runtime field `my_date`. How do I return the date value of the `@timstamp` field in the `my_date` field? The `my_date` field is a `Date` field type.

🙂

-- Cheers, Nils

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 30, 2022, 3:34pm UTC](https://discuss.elastic.co/t/return-emit-timestamp-date-value-in-runtime-field/311001/12 "2022-07-30T15:34:54Z")

</div>

> [@nilei](#):
>
> let us just assume that I want to duplicate the `@timestamp` field into a runtime field. L

Well then I would probably use an alias... not a runtime field...

And remember all dates are actually stored as epoch millis long... all you ever really see is the formatted date output...

I will look at how to duplicate a field later...

Think this will work, but put it as a mapping

```auto
ZonedDateTime zdt = ZonedDateTime.parse(doc['@timestamp'].value.toString());
emit(zdt.toEpochMilli());

```

 ![Screen Shot 2022-07-30 at 8.52.23 AM](https://us1.discourse-cdn.com/elastic/original/3X/b/c/bc43c27d1c7b52534a9fbb08970e6ba934bf6476.png)

I changed the name so I could see them side by side

 ![Screen Shot 2022-07-30 at 8.54.50 AM](https://us1.discourse-cdn.com/elastic/original/3X/f/1/f1388ac229d8b3b530616339579a3723203b09b0.png)

I had to set the date formatters to look the same, That formats the output that is set in the Data View / Index Pattern

 ![Screen Shot 2022-07-30 at 8.55.44 AM](https://us1.discourse-cdn.com/elastic/original/3X/0/0/00cb66db6a04b08c91653baab622cc41f6ed7b29.png)

---

<div class="post-metadata">

**Author:** ![nilei](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nilei/32/90186_2.png) [@nilei](https://discuss.elastic.co/u/nilei)\
**Post date:** [July 30, 2022, 4:04pm UTC](https://discuss.elastic.co/t/return-emit-timestamp-date-value-in-runtime-field/311001/13 "2022-07-30T16:04:44Z")

</div>

Hi Stephen,

when you said ...

> [@stephenb](#):
>
> all dates are actually stored as epoch millis long

... that helped me a lot! I now have what I was looking for.

My solution is the following:

```auto
// Create a zoned datetime 
ZonedDateTime zdt = ZonedDateTime.parse(doc['@timestamp'].value.toString());

```

then:

```auto
// Return as long milli
emit(zdt.toInstant().toEpochMilli());

```

This discussion also helped me to find the correct syntax:

> <https://stackoverflow.com/questions/55645505/how-to-convert-zoneddatetime-to-millisecond-in-java>

-- Cheers, Nils

---

<div class="post-metadata">

**Author:** ![nilei](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nilei/32/90186_2.png) [@nilei](https://discuss.elastic.co/u/nilei)\
**Post date:** [July 30, 2022, 4:05pm UTC](https://discuss.elastic.co/t/return-emit-timestamp-date-value-in-runtime-field/311001/14 "2022-07-30T16:05:13Z")

</div>

Hi Stephen,

great, this is exactly what I was looking for!

Thank you so much!

-- Cheers, Nils

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 30, 2022, 4:13pm UTC](https://discuss.elastic.co/t/return-emit-timestamp-date-value-in-runtime-field/311001/15 "2022-07-30T16:13:35Z")

</div>

Cool that is good too!!

Why you can not just turn around an `emit` the value is unclear to me... (bugging me actually)

---

<div class="post-metadata">

**Author:** ![nilei](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nilei/32/90186_2.png) [@nilei](https://discuss.elastic.co/u/nilei)\
**Post date:** [July 31, 2022, 11:59am UTC](https://discuss.elastic.co/t/return-emit-timestamp-date-value-in-runtime-field/311001/16 "2022-07-31T11:59:12Z")

</div>

> [@stephenb](#):
>
> Why you can not just turn around an `emit` the value is unclear to me

That is what I was trying first, but without any success. So I thought that must be the wrong way.

-- Cheers, Nils

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 28, 2022, 12:00pm UTC](https://discuss.elastic.co/t/return-emit-timestamp-date-value-in-runtime-field/311001/17 "2022-08-28T12:00:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
