# Ruby date parsing

**URL:** <https://discuss.elastic.co/t/ruby-date-parsing/70067>\
**Category:** Logstash\
**Created:** [December 27, 2016, 1:24pm UTC](https://discuss.elastic.co/t/ruby-date-parsing/70067 "2016-12-27T13:24:34Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![aydinnmu](https://avatars.discourse-cdn.com/v4/letter/a/e9bcb4/32.png) [@aydinnmu](https://discuss.elastic.co/u/aydinnmu)\
**Post date:** [December 27, 2016, 1:24pm UTC](https://discuss.elastic.co/t/ruby-date-parsing/70067/1 "2016-12-27T13:24:34Z")

</div>

hi everyone,

ruby section of my config file is like below. this works fine. i set the "timeid" and i mailed to me in body section. But it sends as a UTC time value. my timezone is UTC +3. can i change it ? logstash settings file or anywhere else ?

ruby  
{  
code =\> "  
event.set('timeid',event.sprintf('%{+dd MMMM YYYY HH:mm:ss.SSS}'))  
"  
}

.........

output {

....  
email  
{  
......  
body =\> "Switch says that:\nHost: %{host}\nZaman: %{timeid}\nInfo: %{message}"  
}  
}

output like that

Switch says that:  
Host: 192.168.1.1  
Zaman: 27 December 2016 13:14:21.113  
Info: \<187\>122013: 0.0.0.0: Dec 27 16:14:21.216: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/41, changed state to down

but correct time is 27 December 2016 16:14:21.113

Sincerely

---

<div class="post-metadata">

**Author:** ![jsvd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsvd/32/6203_2.png) [@jsvd](https://discuss.elastic.co/u/jsvd)\
**Post date:** [December 28, 2016, 6:17pm UTC](https://discuss.elastic.co/t/ruby-date-parsing/70067/2 "2016-12-28T18:17:27Z")

</div>

what is the reason for using the ruby code for date parsing and not the date filter itself?

The logstash date filter allows you to set the [timezone of the local machine](https://www.elastic.co/guide/en/logstash/5.1/plugins-filters-date.html#plugins-filters-date-timezone)

For example:

```auto
% echo "12 April 2016 00:00:00.000" | bin/logstash -e "filter { date { match => ['message', 'dd MMMM YYYY HH:mm:ss.SSS'] target => timeid } }"                         
{
    "@timestamp" => 2016-12-28T18:16:44.686Z,
        "timeid" => 2016-04-11T23:00:00.000Z,
      "@version" => "1",
          "host" => "Joaos-MBP-5.lan",
       "message" => "12 April 2016 00:00:00.000",
          "type" => "stdin",
          "tags" => []
}
% echo "12 April 2016 00:00:00.000" | bin/logstash -e "filter { date { match => ['message', 'dd MMMM YYYY HH:mm:ss.SSS'] target => timeid timezone => 'Asia/Tokyo' } }"
{
    "@timestamp" => 2016-12-28T16:59:53.289Z,
        "timeid" => 2016-04-11T15:00:00.000Z,
      "@version" => "1",
          "host" => "Joaos-MBP-5.lan",
       "message" => "12 April 2016 00:00:00.000",
          "type" => "stdin",
          "tags" => []
}

```

---

<div class="post-metadata">

**Author:** ![aydinnmu](https://avatars.discourse-cdn.com/v4/letter/a/e9bcb4/32.png) [@aydinnmu](https://discuss.elastic.co/u/aydinnmu)\
**Post date:** [December 29, 2016, 6:47am UTC](https://discuss.elastic.co/t/ruby-date-parsing/70067/3 "2016-12-29T06:47:33Z")

</div>

hi João

thank you for reply.

when i used date filter , output is not human readable. and i could nout manipulate it.

output like that

![](https://us1.discourse-cdn.com/elastic/original/2X/8/85476daad04a9ea420ee704c45e3edea5c308482.png)

first "zaman" value derived from rubycode and second one derived from timestamp value.

second "zaman" value in config file like this.

```
           date
                    {
                            match => ["@timestamp","ISO8601"]
                            timezone => "Europe/Istanbul"
                  }

```

For example for above output my server time was "Thu Dec 29 17:59:30 +03 2016"  
but "@timestamp" and "timeid" value was 2016-12-28T14:59:30.012Z and 28 December 2016 14:59:30.012

it seems that date filter cannot change the timezone value.

or i misunderstanded date filter manipulation. i expect that when i change timezone by using date filter, @timestamp value should be updated that timezone.

Please correct me if i wrong.

---

<div class="post-metadata">

**Author:** ![aydinnmu](https://avatars.discourse-cdn.com/v4/letter/a/e9bcb4/32.png) [@aydinnmu](https://discuss.elastic.co/u/aydinnmu)\
**Post date:** [December 29, 2016, 7:31am UTC](https://discuss.elastic.co/t/ruby-date-parsing/70067/5 "2016-12-29T07:31:22Z")

</div>

As below i make some test various filter options. Please let me know what i am doing wrong

> % echo "2016-12-29T10:05:30.012Z" | bin/logstash -e "filter { date { match =\> ['message', 'ISO8601'] target =\> timeid timezone =\> 'Etc/UTC'} }"

```
    {
    {
        "@timestamp" => 2016-12-29T07:22:56.555Z,
            "timeid" => 2016-12-29T10:05:30.012Z,
          "@version" => "1",
              "host" => "0.0.0.0",
           "message" => "2016-12-29T10:05:30.012Z",
              "type" => "stdin",
              "tags" => []
    }
    09:22:59.322 [LogStash::Runner] WARN logstash.agent - stopping pipeline {:id=>"main"}
    % echo "2016-12-29T10:05:30.012Z" | bin/logstash -e "filter { date { match => ['message', 'ISO8601'] target => timeid timezone => 'Europe/Istanbul'} }"

    {
        "@timestamp" => 2016-12-29T07:24:55.554Z,
            "timeid" => 2016-12-29T10:05:30.012Z,
          "@version" => "1",
              "host" => "0.0.0.0",
           "message" => "2016-12-29T10:05:30.012Z",
              "type" => "stdin",
              "tags" => []
    }

    % echo "2016-12-29T10:05:30.012Z" | bin/logstash -e "filter { date { match => ['@timestamp', 'ISO8601'] timezone => 'Europe/Istanbul'} }"

    {
        "@timestamp" => 2016-12-29T07:26:41.488Z,
          "@version" => "1",
              "host" => "0.0.0.0",
           "message" => "2016-12-29T10:05:30.012Z",
              "type" => "stdin",
              "tags" => [
            [0] "_dateparsefailure"
        ]
    }
    }

```

---

<div class="post-metadata">

**Author:** ![aydinnmu](https://avatars.discourse-cdn.com/v4/letter/a/e9bcb4/32.png) [@aydinnmu](https://discuss.elastic.co/u/aydinnmu)\
**Post date:** [December 29, 2016, 8:15am UTC](https://discuss.elastic.co/t/ruby-date-parsing/70067/6 "2016-12-29T08:15:49Z")

</div>

Some other tests  
%echo "2016-12-29T08:02:48.695Z" | bin/logstash -e "filter { date { match =\> ['message', 'ISO8601'] target =\> 'message' timezone =\> 'America/New\_York'} }" --log.level debug

```
{
    "@timestamp" => 2016-12-29T08:10:16.706Z,
      "@version" => "1",
          "host" => "0.0.0.0",
       "message" => 2016-12-29T08:02:48.695Z,
          "type" => "stdin",
          "tags" => []
}

%echo "2016-12-29T08:02:48.695Z" | bin/logstash -e "filter { date { locale => en match => ['message', 'ISO8601'] target => 'message' timezone => 'America/New_York'} }" --log.level debug

{
    "@timestamp" => 2016-12-29T08:14:18.582Z,
      "@version" => "1",
          "host" => "0.0.0.0",
       "message" => 2016-12-29T08:02:48.695Z,
          "type" => "stdin",
          "tags" => []
}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 1, 2017, 8:55pm UTC](https://discuss.elastic.co/t/ruby-date-parsing/70067/7 "2017-01-01T20:55:17Z")

</div>

> or i misunderstanded date filter manipulation. i expect that when i change timezone by using date filter, @timestamp value should be updated that timezone.

No. The result of the date filter is always a UTC timestamp. The `timezone` option changes how the source timestamp (that is to be parsed) is interpreted.

Why do you care about the stored representation of the timestamp? Formatting the timestamp for human consumption (including timezone selection) belongs in the presentation layer, not in the database.

---

<div class="post-metadata">

**Author:** ![aydinnmu](https://avatars.discourse-cdn.com/v4/letter/a/e9bcb4/32.png) [@aydinnmu](https://discuss.elastic.co/u/aydinnmu)\
**Post date:** [January 2, 2017, 6:51am UTC](https://discuss.elastic.co/t/ruby-date-parsing/70067/8 "2017-01-02T06:51:47Z")

</div>

Thank you for reply Magnus.

I solved my issue by using below code. It is a not big problem . i just wanna arrange something.

ruby  
{  
code =\> "  
temp=Time.new;  
temp=temp.localtime.strftime ('%d %B %Y %H:%M:%S.%L %z' );  
event.set('timeid',temp);  
"  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 30, 2017, 6:51am UTC](https://discuss.elastic.co/t/ruby-date-parsing/70067/9 "2017-01-30T06:51:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
