# Ruby time.strftime Stripping hours from the time

**URL:** <https://discuss.elastic.co/t/ruby-time-strftime-stripping-hours-from-the-time/283655>\
**Category:** Logstash\
**Created:** [September 8, 2021, 12:24pm UTC](https://discuss.elastic.co/t/ruby-time-strftime-stripping-hours-from-the-time/283655 "2021-09-08T12:24:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bryan\_Hamilton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bryan_hamilton/32/82111_2.png) [@Bryan\_Hamilton](https://discuss.elastic.co/u/Bryan_Hamilton)\
**Post date:** [September 8, 2021, 12:24pm UTC](https://discuss.elastic.co/t/ruby-time-strftime-stripping-hours-from-the-time/283655/1 "2021-09-08T12:24:38Z")

</div>

Hi all,

I am using the following filter to extract only the time from the @timestamp field.

```auto
  ruby {
    code => "event.set('[datetime][time]',event.get('@timestamp').time.strftime('%H:%M:%S'))"
  }

```

Which works exept for the fact that there is an hour difference as shown in the below picture.

 ![logstash_ruby_timestamp](https://us1.discourse-cdn.com/elastic/original/3X/b/8/b83ac6aa783e80362d5de9438a83d56e67648c3e.png)

The local time of the logstash server matches the @timestamp field. Not sure why I am getting this result and how to correct it.

Any help will be appreciated.

Thanks

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [September 8, 2021, 1:24pm UTC](https://discuss.elastic.co/t/ruby-time-strftime-stripping-hours-from-the-time/283655/2 "2021-09-08T13:24:10Z")

</div>

Hi,

In logsatsh, `@timestamp` timezone is UTC and the storage of this timestamp in elasticsearch is also in UTC.  
But in Kibana, by default, all the date types value are converted to the browser's timezone (see in stack managment) this is why your timestamp value is correct but not the nested file.

So i recommend you to use the date filter in logstash to change the type of your value from string to date.

Cad.

---

<div class="post-metadata">

**Author:** ![Bryan\_Hamilton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bryan_hamilton/32/82111_2.png) [@Bryan\_Hamilton](https://discuss.elastic.co/u/Bryan_Hamilton)\
**Post date:** [September 8, 2021, 2:50pm UTC](https://discuss.elastic.co/t/ruby-time-strftime-stripping-hours-from-the-time/283655/3 "2021-09-08T14:50:29Z")

</div>

Hi @Cad , thanks for your reply. I tried converting the `datetime.time` field into `date` type and now time is right but kibana tries to display it as a full date relative to 1970.

 ![logstash_ruby_timestamp1](https://us1.discourse-cdn.com/elastic/original/3X/6/8/683fb986eb5f7a138f1f6f708ad77107f7d54aa2.png)

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [September 8, 2021, 3:46pm UTC](https://discuss.elastic.co/t/ruby-time-strftime-stripping-hours-from-the-time/283655/4 "2021-09-08T15:46:17Z")

</div>

You can edit that in the kibana settings:  
Stack Management \> Index Pattern \> [your index pattern] \> search datetime.time \> edit (with the pen on the right) \> in "Format" select "Date" \> edit "Moment.js format pattern" to only have HH:mm:ss  
And save field

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 6, 2021, 3:46pm UTC](https://discuss.elastic.co/t/ruby-time-strftime-stripping-hours-from-the-time/283655/5 "2021-10-06T15:46:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
