# Timestamp conversion pattern on ingest\_node

**URL:** <https://discuss.elastic.co/t/timestamp-conversion-pattern-on-ingest-node/199231>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 12, 2019, 10:36am UTC](https://discuss.elastic.co/t/timestamp-conversion-pattern-on-ingest-node/199231 "2019-09-12T10:36:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![AndresL](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andresl/32/54070_2.png) [@AndresL](https://discuss.elastic.co/u/AndresL)\
**Post date:** [September 12, 2019, 10:36am UTC](https://discuss.elastic.co/t/timestamp-conversion-pattern-on-ingest-node/199231/1 "2019-09-12T10:36:40Z")

</div>

Hi,  
In an ingest node pipeline, im converting the log event into a timestamp.  
The log event is in this format: 2019-09-11 10:12:11,145  
and the conversion via ingest\_node is removing the TIME: 2019-09-11T00:00:00.000Z

I tried "format": iSO861 (it throws an error) and yyyy-MM-dd hh:mm:ss,SSS, like that (using simulate API)

```
{
 "pipeline": {
   "description": "Parsing LOg4Net Logs",
   "processors": [
     {
       "grok": {
         "field": "message",
         "patterns":["%{TIMESTAMP_ISO8601:logtimestamp};%{DATA:SystemName}"]
       }
     },
     {
      "date" : {
        "field" : "logtimestamp",
        "formats" : ["yyyy-MM-dd hh:mm:ss,SSS"]
      }
    }
   ]
 },
 "docs": [
   {
     "_index": "log4net",
     "_type": "message",
     "_score": 1,
     "_source": {
       "message": "2019-09-11 10:12:11,145;ApplicationName"
     }
   }
 ]
}

```

Result is:  
"\_source": {  
"logtimestamp": "2019-09-11 10:12:11,145",  
"@timestamp": "2019-09-11T00:00:00.000Z",  
"SystemName": "",  
"message": "2019-09-11 10:12:11,145;ApplicationName"

---

<div class="post-metadata">

**Author:** ![AndresL](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andresl/32/54070_2.png) [@AndresL](https://discuss.elastic.co/u/AndresL)\
**Post date:** [September 12, 2019, 2:14pm UTC](https://discuss.elastic.co/t/timestamp-conversion-pattern-on-ingest-node/199231/2 "2019-09-12T14:14:22Z")

</div>

Sorry my bad,  
yyyy-MM-dd HH:mm:ss,SSS should do the trick 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 10, 2019, 2:14pm UTC](https://discuss.elastic.co/t/timestamp-conversion-pattern-on-ingest-node/199231/3 "2019-10-10T14:14:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
