# Timestamp field with local timezone!

**URL:** <https://discuss.elastic.co/t/timestamp-field-with-local-timezone/160238>\
**Category:** Logstash\
**Created:** [December 10, 2018, 7:54pm UTC](https://discuss.elastic.co/t/timestamp-field-with-local-timezone/160238 "2018-12-10T19:54:28Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexwbai](https://avatars.discourse-cdn.com/v4/letter/a/bb73d2/32.png) [@alexwbai](https://discuss.elastic.co/u/alexwbai)\
**Post date:** [December 10, 2018, 7:54pm UTC](https://discuss.elastic.co/t/timestamp-field-with-local-timezone/160238/1 "2018-12-10T19:54:29Z")

</div>

Sorry I know these timezone questions have been beaten to death but I'm really having trouble finding the solution to this problem:

This is what I want to do:

1. Take existing epoch time integer field (eg. 1544471514) and turn it into a timestamp in my LOCAL timezone.
2. I would like to use a TIMEZONE (eg. America/New\_York), not just hardcode an integer offset (eg. localtime('+01:00') because I need to automatically adhere to daylight savings time changes etc.
3. This has nothing to do with the default @timestamp field and I know that date {} filter converts to UTC so I am not using that.

I've read I can use a ruby filter to do this but just need a push in the right direction.

Thanks!  
AlexW

---

<div class="post-metadata">

**Author:** ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)\
**Post date:** [December 11, 2018, 10:19am UTC](https://discuss.elastic.co/t/timestamp-field-with-local-timezone/160238/2 "2018-12-11T10:19:40Z")

</div>

Yeah, I think you have to use ruby filter in order to accomplish what you want.

If I have understood correctly, you need to use 'tzinfo' rubygem in order to handle timezones the way you want to.

So, here's something to push you in the right direction.

```auto
  ruby {
    init => "['date', 'tzinfo'].each(&method(:require))"
    code => "
      tz = TZInfo::Timezone.get('Europe/Helsinki')
      local = tz.utc_to_local(Time.at(event.get('epoch_time_integer_field')))
      event.set('localtime', local.to_s)
      event.set('timezone', tz.to_s)
    "
  }

```

This is completely untested and my ruby skills are close to zero, but it should be enough to give you an idea how to achive your goal. I also have no idea in which format you would like to save the local time etc etc.

Please note, that you need to deliver tzinfo gem to Logstash by yourself.

---

<div class="post-metadata">

**Author:** ![alexwbai](https://avatars.discourse-cdn.com/v4/letter/a/bb73d2/32.png) [@alexwbai](https://discuss.elastic.co/u/alexwbai)\
**Post date:** [December 14, 2018, 8:54pm UTC](https://discuss.elastic.co/t/timestamp-field-with-local-timezone/160238/3 "2018-12-14T20:54:00Z")

</div>

Awesome thanks so much admlko. I'm going to try to test out this code; it's amazing to me this is such a process.

Any tips on installing the tzinfo gem?

Thanks

---

<div class="post-metadata">

**Author:** ![alexwbai](https://avatars.discourse-cdn.com/v4/letter/a/bb73d2/32.png) [@alexwbai](https://discuss.elastic.co/u/alexwbai)\
**Post date:** [December 17, 2018, 6:04pm UTC](https://discuss.elastic.co/t/timestamp-field-with-local-timezone/160238/4 "2018-12-17T18:04:18Z")

</div>

This did the trick. (I dissected the new date time at the end).

filter {  
date {  
match =\> ["epochts", "UNIX"]  
target =\> "timetarget"  
}

ruby {  
init =\> "['date', 'tzinfo'].each(&method(:require))"  
code =\> "  
tz = TZInfo::Timezone.get('US/Eastern')  
local = tz.utc\_to\_local(Time.at(event.get('epochts')))  
event.set('localtime', local.to\_s)  
event.set('timezone', tz.to\_s)  
"  
}

dissect {  
mapping =\> {  
"localtime" =\> "%{year}-%{month}-%{day} %{hour}:%{minute}:%{second} UTC"  
}  
}

}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 14, 2019, 6:04pm UTC](https://discuss.elastic.co/t/timestamp-field-with-local-timezone/160238/5 "2019-01-14T18:04:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
