# Timestamp field issue

**URL:** <https://discuss.elastic.co/t/timestamp-field-issue/304126>\
**Category:** Logstash\
**Created:** [May 6, 2022, 12:35pm UTC](https://discuss.elastic.co/t/timestamp-field-issue/304126 "2022-05-06T12:35:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![shivendra95](https://avatars.discourse-cdn.com/v4/letter/s/eb9ed0/32.png) [@shivendra95](https://discuss.elastic.co/u/shivendra95)\
**Post date:** [May 6, 2022, 12:35pm UTC](https://discuss.elastic.co/t/timestamp-field-issue/304126/1 "2022-05-06T12:35:49Z")

</div>

Hi there,  
I'm using S3 to read input into logstash. The timestamp field generated in Elasticsearch is the time when logs are read from S3 and not the timestamp field of the json log file.  
Below is one object of the json log file read from s3

```auto
{"name":"elk","hostname":"DESKTOP","pid":7440,"level":30,"shortName":"testin","data":{"value":"EN","message":"SET Default language as EN"},"timestamp":"2022-04-27 17:42:51.487","msg":"Default language","v":0}

```

Please help me in assigning the correct timestamp field

---

<div class="post-metadata">

**Author:** ![adrianfusco](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrianfusco/32/111798_2.png) [@adrianfusco](https://discuss.elastic.co/u/adrianfusco)\
**Post date:** [May 6, 2022, 1:15pm UTC](https://discuss.elastic.co/t/timestamp-field-issue/304126/2 "2022-05-06T13:15:55Z")

</div>

Maybe you can use the [date](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html) plugin for this. You can assign a target in the configuration and this target can be the `@timestamp` field.

I'll send `2022-04-27 17:42:51.487` just as a message. Just to give an example of how it works:

You can use the following filtering:

```auto
filter {
    date{
      match => ["message", "yyyy-MM-dd HH:mm:ss.SSS"]
      target => "@timestamp"
    }
} 

```

And checking the output we can see it fits with the data you have in the `timestamp` field.

```auto
{
          "host" => "elastic",
    "@timestamp" => 2022-04-27T17:42:51.487Z,
       "message" => "2022-04-27 17:42:51.487",
          "path" => "/var/log/time4.log",
      "@version" => "1"
}

```

Check the documentation. You can also add the `timezone` as another directive in the filter.

---

<div class="post-metadata">

**Author:** ![shivendra95](https://avatars.discourse-cdn.com/v4/letter/s/eb9ed0/32.png) [@shivendra95](https://discuss.elastic.co/u/shivendra95)\
**Post date:** [May 9, 2022, 7:31am UTC](https://discuss.elastic.co/t/timestamp-field-issue/304126/3 "2022-05-09T07:31:04Z")

</div>

Thanks a lot for you're help. This solution worked.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2022, 7:31am UTC](https://discuss.elastic.co/t/timestamp-field-issue/304126/4 "2022-06-06T07:31:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
