# Timestamp - Filebeat

**URL:** <https://discuss.elastic.co/t/timestamp-filebeat/270900>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 21, 2021, 7:52pm UTC](https://discuss.elastic.co/t/timestamp-filebeat/270900 "2021-04-21T19:52:39Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Akhil2](https://avatars.discourse-cdn.com/v4/letter/a/8797f3/32.png) [@Akhil2](https://discuss.elastic.co/u/Akhil2)\
**Post date:** [April 21, 2021, 7:52pm UTC](https://discuss.elastic.co/t/timestamp-filebeat/270900/1 "2021-04-21T19:52:39Z")

</div>

Hello everyone,

Hope you are doing well! I am exploring the possibilities of log viewing through Kibana. I am using version 7.9.2 for ELK and filebeat as well. so I am sending logs through filebeat directly to Elasticsearch.

now I have multiline logs and following is the specific format of logs.

```auto
Trace: 2021/03/08 11:12:44.749 02 t=9CFE88 c=UNK key=P8 tag= (13007004)
  SourceId: com.ibm.ejs.ras.ManagerAdmin
  ExtendedMessage: TRAS0018I: The trace state has changed. The new trace state is *=info.

```

but I want to use date and time from my logs instead of the timestamp Kibana provides which is the timestamp when logs are processed. Right now I am using dissect processor and the configuration for that is below.

```auto
processors:
   - dissect:
      tokenizer: '%{}: %{+DATE} %{+DATE} %{}' 
      field: "message"
      target_prefix: ""

processors:
  - timestamp:
      field: DATE
      layouts:
         - '2021/03/08 11:12:44.749'
  - drop_fields:
      fields: [DATE]

```

I have two questions here

1. here, I think I am on the right way but I am not sure what am i supposed to put in layouts field so I have put time format from my logs. but it is not working.  
can anyone tell me what am i supposed to do here?
2. is there any way through dissect processor to handle multiline logs. I mean I know I can put if statement to see it as a new log when it sees "TRACE" keyword. can that work?

I hope I was able to explain my problem properly. any help would be much appreciated.

Thanks,  
Akhil

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [April 22, 2021, 12:38am UTC](https://discuss.elastic.co/t/timestamp-filebeat/270900/2 "2021-04-22T00:38:35Z")

</div>

So look here for the timestamp processor docs, [Timestamp | Filebeat Reference [7.12] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/processor-timestamp.html), it looks like u have the right format. Why do u have 2 `processors:` keys, u should only have one.

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [April 22, 2021, 12:43am UTC](https://discuss.elastic.co/t/timestamp-filebeat/270900/3 "2021-04-22T00:43:43Z")

</div>

And look at [Dissect combined with multiline pattern gives errors - #2 by shaunak](https://discuss.elastic.co/t/dissect-combined-with-multiline-pattern-gives-errors/239728/2) to see how to do multi line dissect.

---

<div class="post-metadata">

**Author:** ![Akhil2](https://avatars.discourse-cdn.com/v4/letter/a/8797f3/32.png) [@Akhil2](https://discuss.elastic.co/u/Akhil2)\
**Post date:** [April 25, 2021, 9:21pm UTC](https://discuss.elastic.co/t/timestamp-filebeat/270900/4 "2021-04-25T21:21:58Z")

</div>

Thank you Alex for the right direction. I tried this but it is not working. I tried everything that's why I put this issue here as I needed fresh pair of eyes on this one. may be i missed something. can you see anything wrong apart from the two processor thing. your help would be much appreciated.

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [April 25, 2021, 9:46pm UTC](https://discuss.elastic.co/t/timestamp-filebeat/270900/5 "2021-04-25T21:46:21Z")

</div>

I don't see anything that jumps out at me. Though check the docs on the dissect, when combining words using `%{+...}`, idk if the first value needs the +.

---

<div class="post-metadata">

**Author:** ![Akhil2](https://avatars.discourse-cdn.com/v4/letter/a/8797f3/32.png) [@Akhil2](https://discuss.elastic.co/u/Akhil2)\
**Post date:** [April 25, 2021, 9:50pm UTC](https://discuss.elastic.co/t/timestamp-filebeat/270900/6 "2021-04-25T21:50:54Z")

</div>

Hi Alex,

Actually my logs are in following format. I needed both date and time so I used + to extract both as a date.

Trace: 2021/03/08 11:12:44.733 02 t=9CFE88 c=UNK key=P8 tag= (13007004)

Thanks,  
Akhil

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [April 27, 2021, 1:28pm UTC](https://discuss.elastic.co/t/timestamp-filebeat/270900/7 "2021-04-27T13:28:49Z")

</div>

Ya i had to check the dissect docs to correct myself. Have you remove the multiple `processors` keys?? you should only have 1.

---

<div class="post-metadata">

**Author:** ![Akhil2](https://avatars.discourse-cdn.com/v4/letter/a/8797f3/32.png) [@Akhil2](https://discuss.elastic.co/u/Akhil2)\
**Post date:** [April 27, 2021, 4:34pm UTC](https://discuss.elastic.co/t/timestamp-filebeat/270900/8 "2021-04-27T16:34:26Z")

</div>

yes, I removed two processors. now there is only one. it is fixed now. it was a problem with layout. Thanks for helping me Alex.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 25, 2021, 6:34pm UTC](https://discuss.elastic.co/t/timestamp-filebeat/270900/9 "2021-05-25T18:34:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
