# Timestamp field not populating correctly

**URL:** <https://discuss.elastic.co/t/timestamp-field-not-populating-correctly/176792>\
**Category:** Beats\
**Tags:** functionbeat\
**Created:** [April 14, 2019, 5:48pm UTC](https://discuss.elastic.co/t/timestamp-field-not-populating-correctly/176792 "2019-04-14T17:48:23Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![richwillars](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@richwillars](https://discuss.elastic.co/u/richwillars)\
**Post date:** [April 14, 2019, 5:48pm UTC](https://discuss.elastic.co/t/timestamp-field-not-populating-correctly/176792/1 "2019-04-14T17:48:23Z")

</div>

Hi all. I've got functionbeat working on a AWS lambda, and it's populating all fields correctly apart from the timestamp.

```
{
          "@timestamp": event.ts,
          labels: {
            env: process.env.NODE_CONFIG_ENV,
          },
          service: {
            name: "Foobar"
          },
          event: {
            action: "foo",
            category: "actions",
            created: now.toISOString(),
          },
          user: {
            id: event.userId
        }

```

... etc..

Unfortunately it doesn't seem to pickup the @timestamp field (which is an ISO8601 formatted date string). When I view it in Kibana @timestamp seems to be the date that the record got indexed by Elasticsearch. Event.created is correct as well as the value of @timestamp in 'message' (the raw log).

 ![00](https://us1.discourse-cdn.com/elastic/original/3X/7/5/75b71094fcdd7b9430d9642fcc3e1ac7c3269900.png)

Any ideas on why functionbeat isn't picking up the @timestamp I've specified?

---

<div class="post-metadata">

**Author:** ![richwillars](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@richwillars](https://discuss.elastic.co/u/richwillars)\
**Post date:** [April 14, 2019, 8:43pm UTC](https://discuss.elastic.co/t/timestamp-field-not-populating-correctly/176792/2 "2019-04-14T20:43:04Z")

</div>

Solved! I set "json.overwrite\_keys: true" in the functionbeat config file and that did the trick

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 5, 2019, 10:43am UTC](https://discuss.elastic.co/t/timestamp-field-not-populating-correctly/176792/3 "2019-05-05T10:43:08Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
