# Timestamp and @timestamp not properly mapping

**URL:** <https://discuss.elastic.co/t/timestamp-and-timestamp-not-properly-mapping/99636>\
**Category:** Logstash\
**Created:** [September 6, 2017, 10:31pm UTC](https://discuss.elastic.co/t/timestamp-and-timestamp-not-properly-mapping/99636 "2017-09-06T22:31:16Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Blake\_2112](https://avatars.discourse-cdn.com/v4/letter/b/df705f/32.png) [@Blake\_2112](https://discuss.elastic.co/u/Blake_2112)\
**Post date:** [September 6, 2017, 10:31pm UTC](https://discuss.elastic.co/t/timestamp-and-timestamp-not-properly-mapping/99636/1 "2017-09-06T22:31:16Z")

</div>

I am sure that this has been asked a number of times and from my review of the previous posts nothing seems to be helping me solve my problem.

My JSON has separate date and time fields.

I'm creating an 'eventTime' field in order to combine the date and time into a single reference.  
mutate {  
add\_field =\> {"eventTime" =\> "%{Date} %{Time}"}

I'm then matching the eventTime to the correct format and assigning it to the @timestamp field.

```
    date {
		  match => ["eventTime", "yyyy-mm-dd HH:mm:ss"]
		  #match => ["Time", "MM/dd/yyyy HH:mm:ss"]
		  timezone => "America/Chicago"
		  target => "@timestamp"
         }

```

I am beyond my \_dateparsefailure issues but the eventTime is not matching that of @zikakou1er

"eventTime" =\> "2017-05-09 00:05:08",

"@timestamp" =\> 2017-01-09T06:05:08.000Z,

"Time" =\> "00:05:08",

"Date" =\> "2017-05-09",

I am sure it is something easy that I am just missing but can't seem to get passed my mental block.

Any suggestions would be appreciated.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![kmsasidhar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmsasidhar/32/21838_2.png) [@kmsasidhar](https://discuss.elastic.co/u/kmsasidhar)\
**Post date:** [September 7, 2017, 12:19am UTC](https://discuss.elastic.co/t/timestamp-and-timestamp-not-properly-mapping/99636/2 "2017-09-07T00:19:39Z")

</div>

i just read you are beyond \_dateparsefailure.

It's changing your local time to match UTC by +6 - [http://joda-time.sourceforge.net/timezones.html](http://joda-time.sourceforge.net/timezones.html)

if you want to send output as it is then you may need to use **timezone =\> "Etc/UTC"**

hope this helps.

---

<div class="post-metadata">

**Author:** ![kmsasidhar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmsasidhar/32/21838_2.png) [@kmsasidhar](https://discuss.elastic.co/u/kmsasidhar)\
**Post date:** [September 7, 2017, 12:35am UTC](https://discuss.elastic.co/t/timestamp-and-timestamp-not-properly-mapping/99636/3 "2017-09-07T00:35:37Z")

</div>

you can check this link as well for any hints:

> [@Help parsing \[06/Sep/2017:10:57:42 -0400\]](https://discuss.elastic.co/t/help-parsing-06-sep-2017-10-57-42-0400/99622):
>
> Hello, I am using the following regex to parse out [06/Sep/2017:10:57:42 -0400] [0-9]{2}/[A-z]{3}/[0-9]{4}:[0-9]{2}:[0-9]{2}:[0-9]{2} -[0-9]{4} I used the HTTPDATE grok, but this is placing my timestamp in a CST timezone instead of EST. I am not understanding why logstash is throwing an error on this regex when it is breaking the data as intended. Thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 7, 2017, 5:27am UTC](https://discuss.elastic.co/t/timestamp-and-timestamp-not-properly-mapping/99636/4 "2017-09-07T05:27:38Z")

</div>

- The six-hour difference is because `@timestamp` is UTC and your input timestamp isn't.
- The wrong month problem looks _exactly_ like you had used `DD` in your date pattern instead of `dd`, but according to what you posted you used `dd`. Start by correcting your use of `mm` for the month number so that you use `MM` instead. With that fix you should be fine.

---

<div class="post-metadata">

**Author:** ![Blake\_2112](https://avatars.discourse-cdn.com/v4/letter/b/df705f/32.png) [@Blake\_2112](https://discuss.elastic.co/u/Blake_2112)\
**Post date:** [September 7, 2017, 12:34pm UTC](https://discuss.elastic.co/t/timestamp-and-timestamp-not-properly-mapping/99636/5 "2017-09-07T12:34:45Z")

</div>

Thank you so much.

That resolved the issue and I appreciate your time to respond.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 5, 2017, 12:34pm UTC](https://discuss.elastic.co/t/timestamp-and-timestamp-not-properly-mapping/99636/6 "2017-10-05T12:34:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
