# Split date(yyyymmdd:hhmmss) and convert into default timestamp logstash

**URL:** <https://discuss.elastic.co/t/split-date-yyyymmdd-hhmmss-and-convert-into-default-timestamp-logstash/76986>\
**Category:** Logstash\
**Created:** [March 1, 2017, 1:58pm UTC](https://discuss.elastic.co/t/split-date-yyyymmdd-hhmmss-and-convert-into-default-timestamp-logstash/76986 "2017-03-01T13:58:32Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aditya\_Srivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aditya_srivastava/32/43287_2.png) [@Aditya\_Srivastava](https://discuss.elastic.co/u/Aditya_Srivastava)\
**Post date:** [March 1, 2017, 1:58pm UTC](https://discuss.elastic.co/t/split-date-yyyymmdd-hhmmss-and-convert-into-default-timestamp-logstash/76986/1 "2017-03-01T13:58:32Z")

</div>

I have an input as  
20170301:18544482:INFO 10.0.0.67 ABCLOG sending request  
20170301:18321276:ERROR 10.0.0.67 ABCLOG got response

Above are sample input for my logstash, where input is in foll format  
yyyymmdd:hhmmssSS:loglevel IP message

How to I split the above mentioned timing and convert it into @timestamp format so that i can use the log timing as my default time in ES and Kibana.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 1, 2017, 2:05pm UTC](https://discuss.elastic.co/t/split-date-yyyymmdd-hhmmss-and-convert-into-default-timestamp-logstash/76986/2 "2017-03-01T14:05:58Z")

</div>

Use a grok filter to extract the different parts into their own fields, then use a date filter.

---

<div class="post-metadata">

**Author:** ![Aditya\_Srivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aditya_srivastava/32/43287_2.png) [@Aditya\_Srivastava](https://discuss.elastic.co/u/Aditya_Srivastava)\
**Post date:** [March 2, 2017, 7:02am UTC](https://discuss.elastic.co/t/split-date-yyyymmdd-hhmmss-and-convert-into-default-timestamp-logstash/76986/3 "2017-03-02T07:02:07Z")

</div>

> [@Aditya\_Srivastava](#):
>
> 20170301:18544482:INFO 10.0.0.67 ABCLOG sending reques

I have written a simple grok  
Input-: 20170301:18544482:INFO 10.0.0.67 ABCLOG sending request

%{POSINT:time1}:%{POSINT:time2}:%{WORD:loglevel} %{IP:ip} %{WORD:logdata} %{GREEDYDATA:message}

Output-:  
{  
"time1":"20170301",  
"time2":"18544482",  
"loglevel":"INFO",  
"ip":"10.0.0.67",  
"logdata": "ABCLOG",  
"message": "sending request"

Now how do I use time1 and time2 field to get a timestamp in below format,  
YYYY-MM-ddThh:mm:ss.SS

Later I will use the above timestamp as default in kibana.

PS: How to break time1 and time2 field to get year and date etc is my real query.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 2, 2017, 7:10am UTC](https://discuss.elastic.co/t/split-date-yyyymmdd-hhmmss-and-convert-into-default-timestamp-logstash/76986/4 "2017-03-02T07:10:59Z")

</div>

You can e.g. combine the `time1` and `time2` fields into a single field by adding this to your grok filter:

```nohighlight
add_field => {
  "timestamp" => "%{time1} %{time2}"
}
remove_field => ["time1", "time2"]

```

This'll give you a `timestamp` field containing "20170301 18544482". Feed that to the date filter:

```nohighlight
date {
  match => ["timestamp", "YYYYMMdd HHmmssSS"]
}

```

Although I'm not sure what "18544482" means. Is "82" the number of milliseconds but without a leading zero? What happens if the milliseconds are greater than 100? Will we see e.g. "185444182" then?

---

<div class="post-metadata">

**Author:** ![Aditya\_Srivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aditya_srivastava/32/43287_2.png) [@Aditya\_Srivastava](https://discuss.elastic.co/u/Aditya_Srivastava)\
**Post date:** [March 2, 2017, 9:16am UTC](https://discuss.elastic.co/t/split-date-yyyymmdd-hhmmss-and-convert-into-default-timestamp-logstash/76986/5 "2017-03-02T09:16:10Z")

</div>

Thanks a ton magnus. Usage of date is more clearer to me now.  
And yes for millisec we take only the first 2 digits. If millisec is greater than 100 say 869, then we get this-\> 18544386 number as output.  
We discard the last digit in millisec.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2017, 9:16am UTC](https://discuss.elastic.co/t/split-date-yyyymmdd-hhmmss-and-convert-into-default-timestamp-logstash/76986/6 "2017-03-30T09:16:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
