# @timestamp being represented as string in Logstash 1.5.1

**URL:** <https://discuss.elastic.co/t/timestamp-being-represented-as-string-in-logstash-1-5-1/23881>\
**Category:** Logstash\
**Created:** [June 17, 2015, 9:25pm UTC](https://discuss.elastic.co/t/timestamp-being-represented-as-string-in-logstash-1-5-1/23881 "2015-06-17T21:25:41Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![owenme26](https://avatars.discourse-cdn.com/v4/letter/o/eada6e/32.png) [@owenme26](https://discuss.elastic.co/u/owenme26)\
**Post date:** [June 17, 2015, 9:25pm UTC](https://discuss.elastic.co/t/timestamp-being-represented-as-string-in-logstash-1-5-1/23881/1 "2015-06-17T21:25:42Z")

</div>

Setup:  
I recently upgraded from logstash 1.4.2-1-2c0f5a1 to Logstash 1.5.1-1. I am using the date filter to replace the @timestamp with the event time of the log. I send all input to elasticsearch and I tag certain events and send those tagged events to email output.

Scenario:  
Previously the @timestamp value was being represented as a date value and now it seems to be represented as a string. I see this behavior from the stdout{codec=\>rubydebug} and email output. I include the @timestamp value in my email messages. There has been no modification to my configuration file

@timestamp field in email output  
Prior to upgrading: 2015-06-16 13:08:58 UTC  
Post upgrading: 2015-06-17T20:54:07.000Z

need help getting @timestamp value to be display the same as it was in 1.4.2

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [June 17, 2015, 9:57pm UTC](https://discuss.elastic.co/t/timestamp-being-represented-as-string-in-logstash-1-5-1/23881/2 "2015-06-17T21:57:48Z")

</div>

What was your output?

Changes in 1.5 _require_ the `@timestamp` object to be a time object internally, rather than a string.

You may need to use [sprintf format (for dates)](https://www.elastic.co/guide/en/logstash/current/configuration.html#sprintf) to achieve what you want:

It should be something rather like:

`%{+YYYY-MM-dd HH:mm:ss z}`, though you may have to break it into pieces if the spaces are not honored.

---

<div class="post-metadata">

**Author:** ![owenme26](https://avatars.discourse-cdn.com/v4/letter/o/eada6e/32.png) [@owenme26](https://discuss.elastic.co/u/owenme26)\
**Post date:** [June 17, 2015, 10:33pm UTC](https://discuss.elastic.co/t/timestamp-being-represented-as-string-in-logstash-1-5-1/23881/3 "2015-06-17T22:33:26Z")

</div>

Currently I'm outputing to three locations stdout{codec=\>rubydebg}, email, and elasticsearch. Prior to the upgrade the stdout would color the date green now it is colored white. Emails now have the

> [@owenme26](#):
>
> @timestamp field in email output  
> Prior to upgrading: 2015-06-16 13:08:58 UTC  
> Post upgrading: 2015-06-17T20:54:07.000Z

This is the date filter:  
date {  
match =\> ["eventTime", "YYYY-MM-dd HH:mm:ss"]  
timezone =\> "Etc/UCT"  
}  
are you saying I just need to use the sprintf format for email output?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [June 17, 2015, 10:54pm UTC](https://discuss.elastic.co/t/timestamp-being-represented-as-string-in-logstash-1-5-1/23881/4 "2015-06-17T22:54:11Z")

</div>

That's right!

---

<div class="post-metadata">

**Author:** ![Janet](https://avatars.discourse-cdn.com/v4/letter/j/5e9695/32.png) [@Janet](https://discuss.elastic.co/u/Janet)\
**Post date:** [July 17, 2015, 10:43am UTC](https://discuss.elastic.co/t/timestamp-being-represented-as-string-in-logstash-1-5-1/23881/5 "2015-07-17T10:43:45Z")

</div>

OK, how do a change a field from a string to a time object? I'm getting handed a json input with a @timestamp string. I want to use the value of that @timestamp string to set the date {}., but the match isn't working.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:34am UTC](https://discuss.elastic.co/t/timestamp-being-represented-as-string-in-logstash-1-5-1/23881/6 "2017-07-06T05:34:21Z")

</div>


