# Source of @timestamp field in elasticsearch

**URL:** <https://discuss.elastic.co/t/source-of-timestamp-field-in-elasticsearch/158161>\
**Category:** Elasticsearch\
**Created:** [November 26, 2018, 11:16am UTC](https://discuss.elastic.co/t/source-of-timestamp-field-in-elasticsearch/158161 "2018-11-26T11:16:10Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jogoinar10](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jogoinar10/32/20068_2.png) [@jogoinar10](https://discuss.elastic.co/u/jogoinar10)\
**Post date:** [November 26, 2018, 11:16am UTC](https://discuss.elastic.co/t/source-of-timestamp-field-in-elasticsearch/158161/1 "2018-11-26T11:16:10Z")

</div>

I have an elastic setup which consist of Beats, Logstash and Elasticsearch.

I just wanna know if what application generates the @timestamp field?

Is it generated by elasticsearch at the time it was index? or at the time that filebeat compiles the file logs?

TIA 😃

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 26, 2018, 12:01pm UTC](https://discuss.elastic.co/t/source-of-timestamp-field-in-elasticsearch/158161/2 "2018-11-26T12:01:51Z")

</div>

Well. It can come from different sources:

- Metricbeat for example can generate it
- Logstash can extract the date from a log line with some grok/date filters. The log line can come from filebeat though.
- Elasticsearch as well if you are using ingest pipelines or filebeat modules such as the nginx module

So I'd say that it depends 😉

---

<div class="post-metadata">

**Author:** ![jogoinar10](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jogoinar10/32/20068_2.png) [@jogoinar10](https://discuss.elastic.co/u/jogoinar10)\
**Post date:** [November 26, 2018, 12:03pm UTC](https://discuss.elastic.co/t/source-of-timestamp-field-in-elasticsearch/158161/3 "2018-11-26T12:03:55Z")

</div>

Thank you for the info. but let's say that my data came from filebeat or winlogbeat. Does the beat generates the data?

---

<div class="post-metadata">

**Author:** ![jogoinar10](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jogoinar10/32/20068_2.png) [@jogoinar10](https://discuss.elastic.co/u/jogoinar10)\
**Post date:** [November 26, 2018, 12:34pm UTC](https://discuss.elastic.co/t/source-of-timestamp-field-in-elasticsearch/158161/4 "2018-11-26T12:34:26Z")

</div>

> [@jogoinar10](#):
>
> Thank you for the info. but let's say that my data came from filebeat or winlogbeat. Does the beat generates the data?

Thank you for the info. but let's say that my data came from filebeat or winlogbeat. Does the beat generates the data?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 26, 2018, 4:39pm UTC](https://discuss.elastic.co/t/source-of-timestamp-field-in-elasticsearch/158161/5 "2018-11-26T16:39:29Z")

</div>

I did not check the details. I supposed that for winlogbeat beats generate the `@timestamp` field according to the event date.

For filebeat, it depends. If you are streaming whatever unknown log file ie `/myapp/app.log` then `@timestamp` is most likely the date the event has been collected by filebeat and not the event date itself.

Better to ask in #beats:filebeat to get more info on this IMO.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2018, 4:39pm UTC](https://discuss.elastic.co/t/source-of-timestamp-field-in-elasticsearch/158161/6 "2018-12-24T16:39:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
