# Time in IST for log-rotation - Logstash

**URL:** <https://discuss.elastic.co/t/time-in-ist-for-log-rotation-logstash/211612>\
**Category:** Logstash\
**Created:** [December 12, 2019, 10:15am UTC](https://discuss.elastic.co/t/time-in-ist-for-log-rotation-logstash/211612 "2019-12-12T10:15:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![singhankit.iem](https://avatars.discourse-cdn.com/v4/letter/s/f04885/32.png) [@singhankit.iem](https://discuss.elastic.co/u/singhankit.iem)\
**Post date:** [December 12, 2019, 10:15am UTC](https://discuss.elastic.co/t/time-in-ist-for-log-rotation-logstash/211612/1 "2019-12-12T10:15:13Z")

</div>

I have configured file-beat on all the App servers and Logstash in a centralized server for the log rotation. The config file in Log rotation is

input {  
beats {  
port =\> 5044  
}  
}  
filter{  
mutate {  
remove\_field =\> ["agent","input","host","architecture","containerized","mac","os","@version","log","ecs","offset"]  
}  
}  
output {  
file {  
path =\> "/log/sync/ims-v1/%{+dd-MM-yyyy}/%{+HH}-ims.log"  
}  
}

-- In OUTPUT: Logstash to create a file/directory depending on an hourly basis for the logs: **but currently it is creating it in GMT can I do it according to IST**.

as: log/sync/ims-v1/12-12-2019/10-ims.log -- Here the 10-ims.log file is getting created at 15:30 IST (According to my use case it should be as: log/sync/ims-v1/12-12-2019/15-ims.log)

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![ITIC](https://avatars.discourse-cdn.com/v4/letter/i/90ced4/32.png) [@ITIC](https://discuss.elastic.co/u/ITIC)\
**Post date:** [December 12, 2019, 11:50am UTC](https://discuss.elastic.co/t/time-in-ist-for-log-rotation-logstash/211612/2 "2019-12-12T11:50:53Z")

</div>

HI

If what you want is to name your files using the date and time in your local time, you might try something like this:

```auto
filter {
  [... your stuff goes here...]
  ruby {
    code => "
      event.set('filename', event.get('@timestamp').time.localtime.strftime('%Y-%m-%d/%H'))
    "
  }
}
	
output {
  file {
    path => "/log/sync/ims-v1/%{filename}-ims.log"
  }
}	

```

Haven't tried this code but I use a similar construct to generate local time from `timestamp` (or from any date field).

Hope this helps.

---

<div class="post-metadata">

**Author:** ![singhankit.iem](https://avatars.discourse-cdn.com/v4/letter/s/f04885/32.png) [@singhankit.iem](https://discuss.elastic.co/u/singhankit.iem)\
**Post date:** [December 12, 2019, 1:28pm UTC](https://discuss.elastic.co/t/time-in-ist-for-log-rotation-logstash/211612/3 "2019-12-12T13:28:44Z")

</div>

Thanks alot,

It did worked 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 9, 2020, 1:29pm UTC](https://discuss.elastic.co/t/time-in-ist-for-log-rotation-logstash/211612/4 "2020-01-09T13:29:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
