# @Timestamp does not appear when creating index

**URL:** <https://discuss.elastic.co/t/timestamp-does-not-appear-when-creating-index/224487>\
**Category:** Logstash\
**Tags:** elastic-stack-monitoring\
**Created:** [March 20, 2020, 8:51pm UTC](https://discuss.elastic.co/t/timestamp-does-not-appear-when-creating-index/224487 "2020-03-20T20:51:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![lfuentes](https://avatars.discourse-cdn.com/v4/letter/l/df705f/32.png) [@lfuentes](https://discuss.elastic.co/u/lfuentes)\
**Post date:** [March 20, 2020, 8:51pm UTC](https://discuss.elastic.co/t/timestamp-does-not-appear-when-creating-index/224487/1 "2020-03-20T20:51:09Z")

</div>

Good morning, I have a problem creating an index, it happens that @timestamp does not appear to me, this is an example of the date in the log file:

```
####<Mar 15, 2020 11:44:28 PM CLST> <Info> <Health> <vp1mw220> <osb_Teleton02> <weblogic.GCMonitor> <<anonymous>> <> <48acf31c77bb5441:19522313:170cc2728eb:-7ffd-0000000000000033> <1584326668140> <BEA-310002> <41% of the total memory in the server is free>
####<Mar 15, 2020 11:45:28 PM CLST> <Info> <Health> <vp1mw220> <osb_Teleton02> <weblogic.GCMonitor> <<anonymous>> <> <48acf31c77bb5441:19522313:170cc2728eb:-7ffd-0000000000000033> <1584326728141> <BEA-310002> <20% of the total memory in the server is free>

```

This is the filter I am using:

filter {

```
if [document_type] == "busteleton" {

    grok {

        match => {"message" => [

            "(?m)%{COMMON_LOG:date}%{DATA:trash} <%{WORD:level}> <%{WORD:tipo}> <%{WORD:maquina}> <%{WORD:instancia}> <%{DATA:trash}> <%{DATA:trash}> <%{DATA:trash}> <%{DATA:trash}> <%{DATA:trash}> <%{DATA:bea}> %{GREEDYDATA:traza}",

            "(?m)%{COMMON_LOG:date}%{DATA:trash} <%{WORD:level}> <%{WORD:tipo}> <%{DATA:bea}> %{GREEDYDATA:traza}"

        ]}

    }

    mutate {

        add_field => { "fecha_bus" => "%{date}" }

        remove_field => ["tags","message","agent","input","type","trash","host","log","file","path","offset","ecs","version","@version"]

        rename => {"@timestamp" => "processTime"}

    }

    date {

        match => ["fecha_bus", "MMM d, yyyy hh:mm:ss aa"]

        target => "@timestamp"

    }

}

```

}

When I want to create an index, only "processtime" appears, please help me

Thanks

Luis

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 22, 2020, 5:23pm UTC](https://discuss.elastic.co/t/timestamp-does-not-appear-when-creating-index/224487/2 "2020-03-22T17:23:32Z")

</div>

> [@lfuentes](#):
>
> rename =\> {"@timestamp" =\> "processTime"}

I am puzzled. You change the name of the @timestamp field to processTime and then ask why you have a field called processTime instead of @timestamp. If you want both then use copy or add\_field instead of rename.

---

<div class="post-metadata">

**Author:** ![lfuentes](https://avatars.discourse-cdn.com/v4/letter/l/df705f/32.png) [@lfuentes](https://discuss.elastic.co/u/lfuentes)\
**Post date:** [March 22, 2020, 8:56pm UTC](https://discuss.elastic.co/t/timestamp-does-not-appear-when-creating-index/224487/3 "2020-03-22T20:56:10Z")

</div>

Hello friend, what happens is that I have this type of date "Mar 15, 2020 11:46:28 PM CLST" and I can not parse it, if someone can support me I would appreciate it, I could not match.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 22, 2020, 11:29pm UTC](https://discuss.elastic.co/t/timestamp-does-not-appear-when-creating-index/224487/4 "2020-03-22T23:29:51Z")

</div>

CLST is not a timezone name that Joda [supports](http://joda-time.sourceforge.net/timezones.html). I suggest you remove it

```
mutate { gsub => ["fecha_bus", " CLST$", ""] }

```

and also remove the " aa" at the end of you date filter pattern.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2020, 11:29pm UTC](https://discuss.elastic.co/t/timestamp-does-not-appear-when-creating-index/224487/5 "2020-04-19T23:29:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
