# Sort by time received instead of timestamp

**URL:** <https://discuss.elastic.co/t/sort-by-time-received-instead-of-timestamp/308992>\
**Category:** Elasticsearch\
**Created:** [July 6, 2022, 8:44am UTC](https://discuss.elastic.co/t/sort-by-time-received-instead-of-timestamp/308992 "2022-07-06T08:44:45Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![MADxHAWK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madxhawk/32/103219_2.png) [@MADxHAWK](https://discuss.elastic.co/u/MADxHAWK)\
**Post date:** [July 6, 2022, 8:44am UTC](https://discuss.elastic.co/t/sort-by-time-received-instead-of-timestamp/308992/1 "2022-07-06T08:44:45Z")

</div>

Hello,

im using ELK-Stack to search through Cisco logs received by filebeat from our loghost.  
the problem is, i only can sort the discover by Timestamp from Elasticsearch and not by the timestamp the message was received from the loghost.  
Usualy its not a big deal cause the timestamps doenst differ much, but if you have rebuild an index the timestamps are totaly out of order.  
So can i use the original timestamp the log was received by the loghost instead of the timestamp elasticsearch received the log from filebeat?

I cant let elasticsearch receive the logs directly cause i would have to change the config of about 400-500 switches to send the logs to elasticsearch and the loghost.

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [July 6, 2022, 10:35am UTC](https://discuss.elastic.co/t/sort-by-time-received-instead-of-timestamp/308992/2 "2022-07-06T10:35:05Z")

</div>

How about create Data View ("Index pattern" for older versions) with "original timestamp" as the time field?

---

<div class="post-metadata">

**Author:** ![MADxHAWK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madxhawk/32/103219_2.png) [@MADxHAWK](https://discuss.elastic.co/u/MADxHAWK)\
**Post date:** [July 6, 2022, 11:22am UTC](https://discuss.elastic.co/t/sort-by-time-received-instead-of-timestamp/308992/3 "2022-07-06T11:22:49Z")

</div>

Well i would like to do that but there are some problems

1. cisco logfile timestamps are in the format Jul 6 2022 10:36:01.447 UTC  
and i can only disaable the year, the miliseconds and the timezone so the timestamp would change to Jul 6 10:36:01. but i cant change the format itself.

2. when i create a Data View i can only select @timestamp or --- i dont want to use time filter --- but not the field i want to use as a timestamp

so this seems to be no option or im doing something terribly wrong.

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [July 6, 2022, 11:40am UTC](https://discuss.elastic.co/t/sort-by-time-received-instead-of-timestamp/308992/4 "2022-07-06T11:40:24Z")

</div>

Simple sorting is not enough?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/7/470a51998d3347a5cae12eb2f4e3cd3114df2c5a.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/e/5e5f8d5a45c7c9056a544949348131c913ab4c83.png)

---

<div class="post-metadata">

**Author:** ![MADxHAWK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madxhawk/32/103219_2.png) [@MADxHAWK](https://discuss.elastic.co/u/MADxHAWK)\
**Post date:** [July 7, 2022, 6:01am UTC](https://discuss.elastic.co/t/sort-by-time-received-instead-of-timestamp/308992/5 "2022-07-07T06:01:19Z")

</div>

im using Elasticsearch 8 and @timestamp is the only field with an option to sort a-z or z-a  
at all other fields sort is greyed out and therefore not available and thats the problem.

---

<div class="post-metadata">

**Author:** ![matschaffer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matschaffer/32/95396_2.png) [@matschaffer](https://discuss.elastic.co/u/matschaffer)\
**Post date:** [July 8, 2022, 6:14am UTC](https://discuss.elastic.co/t/sort-by-time-received-instead-of-timestamp/308992/6 "2022-07-08T06:14:53Z")

</div>

I'd recommend using [Date processor | Elasticsearch Guide [master] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/master/date-processor.html) to convert the cisco timestamps to date type. Then you should be able to use it as a sort in a data view. Or by default it will write to `@timestamp` which might fit your needs.

If you still want to time the log was written to ES you can use a set processor for that as shown on [Event Fields | Elastic Common Schema (ECS) Reference [8.3] | Elastic](https://www.elastic.co/guide/en/ecs/current/ecs-event.html#field-event-ingested)

---

<div class="post-metadata">

**Author:** ![MADxHAWK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madxhawk/32/103219_2.png) [@MADxHAWK](https://discuss.elastic.co/u/MADxHAWK)\
**Post date:** [July 15, 2022, 8:06am UTC](https://discuss.elastic.co/t/sort-by-time-received-instead-of-timestamp/308992/7 "2022-07-15T08:06:40Z")

</div>

Thank you @matschaffer , that solved the problem even cisco seems to be not shure what timeformat they should use, but i think it works now.  
Anyway that seemd to raised some other problems like reading loglines multiple times but thats for another topic.

Thanks again for that hint.

---

<div class="post-metadata">

**Author:** ![matschaffer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matschaffer/32/95396_2.png) [@matschaffer](https://discuss.elastic.co/u/matschaffer)\
**Post date:** [July 19, 2022, 2:16am UTC](https://discuss.elastic.co/t/sort-by-time-received-instead-of-timestamp/308992/8 "2022-07-19T02:16:59Z")

</div>

You're very welcome and glad you got it sorted out!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 16, 2022, 2:17am UTC](https://discuss.elastic.co/t/sort-by-time-received-instead-of-timestamp/308992/9 "2022-08-16T02:17:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
