# Time format of output

**URL:** <https://discuss.elastic.co/t/time-format-of-output/197643>\
**Category:** Elasticsearch\
**Created:** [September 2, 2019, 4:45am UTC](https://discuss.elastic.co/t/time-format-of-output/197643 "2019-09-02T04:45:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![JohnM](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johnm/32/49468_2.png) [@JohnM](https://discuss.elastic.co/u/JohnM)\
**Post date:** [September 2, 2019, 4:45am UTC](https://discuss.elastic.co/t/time-format-of-output/197643/1 "2019-09-02T04:45:04Z")

</div>

In the logstash (ver 7) output I have

```
 index => "logstash-asterisk-%{+YYYY.MM.dd.HH}"

```

and I was expecting ES (ver 7) makes index something like logstash-asterisk-2019.09.02.15 for 3pm.

but when I look at kibana hour section just starts from 01, 02, and 03.  
logstash-asterisk-2019.09.02.01  
logstash-asterisk-2019.09.02.02  
logstash-asterisk-2019.09.02.03

Is this how it is designed or something wrong?  
I was expecting this.  
logstash-asterisk-2019.09.02.15 for 3pm.  
logstash-asterisk-2019.09.02.16 for 4pm.  
logstash-asterisk-2019.09.02.17 for 5pm.

Thanks for your help in advance.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 2, 2019, 4:55am UTC](https://discuss.elastic.co/t/time-format-of-output/197643/2 "2019-09-02T04:55:30Z")

</div>

Can you show a document together with the name of the index it ended up in? Be aware that this is based on the @timestamp field, which is in UTC.

As a side note - how come you are using hourly indices? Do you have an extreme amount of data coming in or a very short retention period? If not, be aware that this generally results in a lot of indices and shards which can cause performance problems down the line. Have a look at [this blog post](https://www.elastic.co/blog/how-many-shards-should-i-have-in-my-elasticsearch-cluster) for guidance.

---

<div class="post-metadata">

**Author:** ![JohnM](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johnm/32/49468_2.png) [@JohnM](https://discuss.elastic.co/u/JohnM)\
**Post date:** [September 2, 2019, 11:44pm UTC](https://discuss.elastic.co/t/time-format-of-output/197643/3 "2019-09-02T23:44:32Z")

</div>

Ah.. It is UTC. It makes sense. Accidentally I started hourly index at 1 am in UTC so it started from 01.  
We are collecting kamailio log. It creates 60GB every hour so we can keep only last a few hours log.  
Thanks for your help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 30, 2019, 11:44pm UTC](https://discuss.elastic.co/t/time-format-of-output/197643/4 "2019-09-30T23:44:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
