# Split timestamp to date and time

**URL:** <https://discuss.elastic.co/t/split-timestamp-to-date-and-time/201739>\
**Category:** Logstash\
**Created:** [October 1, 2019, 7:13am UTC](https://discuss.elastic.co/t/split-timestamp-to-date-and-time/201739 "2019-10-01T07:13:42Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mohamad.faisel](https://avatars.discourse-cdn.com/v4/letter/m/258eb7/32.png) [@mohamad.faisel](https://discuss.elastic.co/u/mohamad.faisel)\
**Post date:** [October 1, 2019, 7:13am UTC](https://discuss.elastic.co/t/split-timestamp-to-date-and-time/201739/1 "2019-10-01T07:13:42Z")

</div>

Hi,

How do I split timestamp field and store the result into timestamp\_date and timestamp\_time in logstash.

Thank you.

---

<div class="post-metadata">

**Author:** ![mohamad.faisel](https://avatars.discourse-cdn.com/v4/letter/m/258eb7/32.png) [@mohamad.faisel](https://discuss.elastic.co/u/mohamad.faisel)\
**Post date:** [October 2, 2019, 2:42am UTC](https://discuss.elastic.co/t/split-timestamp-to-date-and-time/201739/2 "2019-10-02T02:42:58Z")

</div>

I manage to get both date and time into saperate variables. Here is my script:

```auto
#Logstash filter
#/etc/logstash/patterns/ contains pfsense2-4-grok downloaded from https://github.com/patrickjennings/logstash-pfsense/blob/master/patterns/pfsense2-4.grok
filter{
    grok{
        patterns_dir => "/etc/logstash/patterns"
        match => [
            "message", "%{TIMESTAMP_ISO8601:timestamp} %{WORD:pf_host} filterlog: %{PFSENSE_LOG_DATA}%{PFSENSE_IP_SPECIFIC_DATA}%{PFSENSE_IP_DATA}%{PFSENSE_PROTOCOL_DATA}",
            "message", "%{TIMESTAMP_ISO8601:timestamp} %{WORD:pf_host} filterlog: %{PFSENSE_LOG_DATA}%{PFSENSE_IPv4_SPECIFIC_DATA_ECN}%{PFSENSE_IP_DATA}%{PFSENSE_PROTOCOL_DATA}"
        ]
    }
    mutate {
        # Add 2 fields for date and time and set their value to timestamp
        add_field => { "timestamp_date"=> "%{timestamp}" }
        add_field => { "timestamp_time"=> "%{timestamp}" }
    }
    mutate {
        # Remove time section
        gsub => ["timestamp_date", "T\d{2}:\d{2}:\d{2}((.\d{3}Z)|([+\-]\d{2}:\d{2}))", ""]
    }
    mutate {
        # Remove date section
        gsub => ["timestamp_time", "\d{4}-\d{2}-\d{2}T", ""]
    }
    date {
        match => ["timestamp", "ISO8601"]
    }
}

```

However, I notice that my @timestamp is wrong. The system took the current date instead of the logged date. I might have missed some config lines here.

Please assist.

Thanks.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 2, 2019, 12:35pm UTC](https://discuss.elastic.co/t/split-timestamp-to-date-and-time/201739/3 "2019-10-02T12:35:29Z")

</div>

What does the [timestamp] field look like?

---

<div class="post-metadata">

**Author:** ![mohamad.faisel](https://avatars.discourse-cdn.com/v4/letter/m/258eb7/32.png) [@mohamad.faisel](https://discuss.elastic.co/u/mohamad.faisel)\
**Post date:** [October 3, 2019, 2:06am UTC](https://discuss.elastic.co/t/split-timestamp-to-date-and-time/201739/4 "2019-10-03T02:06:19Z")

</div>

The image was below taken from Kibana showing all the extracted fields.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/c/dc71eaa16c4d0fbfc52912ef60f854d62a06d8e3.png)

From the above image, please note the following :

- Text highlighted in **RED** is **@timestamp** field which refers to the execution time
- Text highlighted in **BLUE** is **timestamp** field which refers to the actual event time extracted from the log

Question : How do I make **@timestamp** having the same value as **timestamp**?

Thank you.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 3, 2019, 2:10pm UTC](https://discuss.elastic.co/t/split-timestamp-to-date-and-time/201739/5 "2019-10-03T14:10:11Z")

</div>

Please do not post pictures of text, just post the text. You can copy and paste it from the JSON tab in Kibana. Use markdown to make sure it is formatted correctly in the preview pane to the right of the edit pane.

---

<div class="post-metadata">

**Author:** ![mohamad.faisel](https://avatars.discourse-cdn.com/v4/letter/m/258eb7/32.png) [@mohamad.faisel](https://discuss.elastic.co/u/mohamad.faisel)\
**Post date:** [October 4, 2019, 2:59am UTC](https://discuss.elastic.co/t/split-timestamp-to-date-and-time/201739/6 "2019-10-04T02:59:33Z")

</div>

Dear Badger,

Sorry about that. Will do as recommended in the future.

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 1, 2019, 2:59am UTC](https://discuss.elastic.co/t/split-timestamp-to-date-and-time/201739/7 "2019-11-01T02:59:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
