# Ruby plugin and timezone issue

**URL:** <https://discuss.elastic.co/t/ruby-plugin-and-timezone-issue/106138>\
**Category:** Logstash\
**Created:** [November 2, 2017, 8:34am UTC](https://discuss.elastic.co/t/ruby-plugin-and-timezone-issue/106138 "2017-11-02T08:34:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [November 2, 2017, 8:34am UTC](https://discuss.elastic.co/t/ruby-plugin-and-timezone-issue/106138/1 "2017-11-02T08:34:27Z")

</div>

Hi all,  
I had to calculate a new date field: given a timestamp and a offset I need to set a new field with the value **_timestamp+offset_**  
I solved the problem but I'm sure that there is a better way to do it.  
I use ruby code in order to calculate the new field, but it is calculated with the wrong timezone; then I use a temporary field and a date plugin again.  
Anyone can help me to improve the solution?  
(below the details)  
Thanks a lot  
Regards  
Anna

logstash.conf

1. First I get the timestamp

2. Convert the offset to integer

3. Calculate new temp field with ruby plugin. It returns a field of type "date" but with the wrong timezone

4. Using ruby I get a another temp field of type keyword. Using strftime a get the correct timezone

5. Finally I get the desired field using the date plugin

Here are the mappings

```
  "ts_stop": {
    "type": "date"
  },
  "ts_temp": {
    "type": "date"
  },
  "ts_temp2": {
    "type": "text",
    "fields": {
      "keyword": {
        "type": "keyword",
        "ignore_above": 256
      }
    }
```

---

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [November 6, 2017, 3:07pm UTC](https://discuss.elastic.co/t/ruby-plugin-and-timezone-issue/106138/2 "2017-11-06T15:07:25Z")

</div>

I got it working. No TZ mistmacht

```
 date {
            match => ["ts", "yyyyMMddHHmmss"]
            timezone => "Europe/Andorra"
            remove_field => ["ts"]
    }
    mutate {
            convert => { "duration" => "integer" }
    }
    ruby {
             code => "event.set('ts_start',event.get('@timestamp'))"
    }

    if [duration]{
            ruby {
                    code => "event.set('ts_stop',event.get('@timestamp')+event.get('duration'))"
            }
            ruby {
                    code => "event.set('@timestamp',event.get('ts_stop'))"
            }

    }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 4, 2017, 3:08pm UTC](https://discuss.elastic.co/t/ruby-plugin-and-timezone-issue/106138/3 "2017-12-04T15:08:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
