# Time Filter field name: @timestamp

**URL:** <https://discuss.elastic.co/t/time-filter-field-name-timestamp/176232>\
**Category:** Logstash\
**Created:** [April 10, 2019, 1:57pm UTC](https://discuss.elastic.co/t/time-filter-field-name-timestamp/176232 "2019-04-10T13:57:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Guy\_Shar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guy_shar/32/43086_2.png) [@Guy\_Shar](https://discuss.elastic.co/u/Guy_Shar)\
**Post date:** [April 10, 2019, 1:57pm UTC](https://discuss.elastic.co/t/time-filter-field-name-timestamp/176232/1 "2019-04-10T13:57:03Z")

</div>

Am trying to setup a graph using the date and time values from my log file.  
The date and time format is as follow:  
16/09/2014 11:54:55

I would like this value to be populated into the field: @timestamp, as at the moment it contains the index action time, and not the log record time.

When i create an index pattern i only presented with this field @timestamp as an option.

I have created another field in the logstash conf file: called logdate, hoping it will be available for selection, but from some reason this field type is text.

```
"logdate": {
      "type": "text",
      "fields": {
        "keyword": {
          "type": "keyword",
          "ignore_above": 256
        }
      }
    },

```

This is the logstash config of this field:  
filter  
{  
grok{  
match =\> {"message" =\> "%{GREEDYDATA:filename}: %{DATESTAMP:logdate} %{GREEDYDATA:dummy}: %{GREEDYDATA:dummy1}databaseMatch=%{GREEDYDATA:source}&EndTag=%{GREEDYDATA:dummy2}&FieldText=%{GREEDYDATA:filter}&highlight=%{GREEDYDATA:dummy3}&Text=%{GREEDYDATA:searchterms}&TotalResults=true&userID=%{GREEDYDATA:userid}&WeighFieldText="}  
}  
date {  
match =\> ["logdate", "MM/dd/YYYY HH:mm:ss"]  
target =\> "logdate"  
}  
}

I have two questions:

1. How can i set the default @timestamp value to the log file date ?
2. How can i get the type of the logdate to be type date as opposed to Text ?

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 11, 2019, 12:35pm UTC](https://discuss.elastic.co/t/time-filter-field-name-timestamp/176232/2 "2019-04-11T12:35:38Z")

</div>

If your field format is 16/09/2014 11:54:55, then that is "dd/MM/YYYY HH:mm:ss", not "MM/dd/YYYY HH:mm:ss".

If you want to parse that into @timestamp then remove the target option from the date filter. You can then overwrite the logdate field using a mutate filter.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 9, 2019, 12:35pm UTC](https://discuss.elastic.co/t/time-filter-field-name-timestamp/176232/3 "2019-05-09T12:35:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
