# @timestamp conversion

**URL:** <https://discuss.elastic.co/t/timestamp-conversion/54640>\
**Category:** Logstash\
**Created:** [July 4, 2016, 11:22am UTC](https://discuss.elastic.co/t/timestamp-conversion/54640 "2016-07-04T11:22:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Craig\_Botha](https://avatars.discourse-cdn.com/v4/letter/c/94ad74/32.png) [@Craig\_Botha](https://discuss.elastic.co/u/Craig_Botha)\
**Post date:** [July 4, 2016, 11:22am UTC](https://discuss.elastic.co/t/timestamp-conversion/54640/1 "2016-07-04T11:22:18Z")

</div>

Hello Logstash community

I set up ELK (filebeat\>logstash\>elasticsearch\>kibana) on a Windows 2012 server last week, and have been trying to configure Logstash to parse my logs correctly. I've got it mostly correct, but seem to be having trouble with the timestamp conversion.

**Overview**  
An example of the log message I'm trying to parse is

> 2016-07-04 12:57:03,223 CAT INFO log.kernel 1019:0005 [ebx-scheduler-worker-1] Processing Product Pid: 655

My logstash filter is:

> filter {  
> grok {  
> patterns\_dir =\> ["./patterns"]  
> match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:log\_timestamp} CAT %{LOGLEVEL:loglevel}\s\*log.%{WORD:logtype} %{NUMBER}:%{NUMBER} %{SYSLOG5424SD:thread} %{GREEDYDATA:log\_message}" }  
> }  
> date{  
> match =\> ["log\_timestamp", "YYYY-MM-DD HH:mm:ss,SSS"]  
> }
> 
> }

and the output for this log entry is:

> {  
> "message": "2016-07-04 12:57:03,223 CAT INFO log.kernel 1019:0005 [ebx-scheduler-worker-1] Processing Product Pid: 655",  
> "@version": "1",  
> "@timestamp": "2016-01-04T10:57:03.223Z",  
> "count": 1,  
> "fields": null,  
> "input\_type": "log",  
> "beat": {  
> "hostname": "ZAAFHVMEBX01",  
> "name": "ZAAFHVMEBX01"  
> },  
> "source": "C:\EBX5\EBXHome\ebxLog\kernel.log",  
> "offset": 5446815,  
> "type": "log",  
> "host": "ZAAFHVMEBX01",  
> "tags": ["beats\_input\_codec\_plain\_applied"],  
> "log\_timestamp": "2016-07-04 12:57:03,223",  
> "loglevel": "INFO",  
> "logtype": "kernel",  
> "thread": "[ebx-scheduler-worker-1]",  
> "log\_message": "Processing Product Pid: 655"  
> }

**Problem**

The field log\_timestamp is being correctly identified:

> "log\_timestamp": "2016-07-04 12:57:03,223"

but there appears to be a problem with it's conversion to @timestamp:

> "@timestamp": "2016-01-04T10:57:03.223Z"

The date in the log\_timestamp field is 4 July 2016, while the date in the @timestamp field is 4 January 2016.

Please can someone assist me with getting the correct date conversion.

Kind regards  
Craig

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 4, 2016, 11:26am UTC](https://discuss.elastic.co/t/timestamp-conversion/54640/2 "2016-07-04T11:26:00Z")

</div>

> match =\> ["log\_timestamp", "YYYY-MM-DD HH:mm:ss,SSS"]

Change to:

match =\> ["log\_timestamp", "YYYY-MM-dd HH:mm:ss,SSS"]

---

<div class="post-metadata">

**Author:** ![Craig\_Botha](https://avatars.discourse-cdn.com/v4/letter/c/94ad74/32.png) [@Craig\_Botha](https://discuss.elastic.co/u/Craig_Botha)\
**Post date:** [July 4, 2016, 11:58am UTC](https://discuss.elastic.co/t/timestamp-conversion/54640/3 "2016-07-04T11:58:57Z")

</div>

Thanks @magnusbaeck

Appreciate the assist.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:49am UTC](https://discuss.elastic.co/t/timestamp-conversion/54640/4 "2017-07-06T04:49:45Z")

</div>


