# Timestamp format while overwriting

**URL:** <https://discuss.elastic.co/t/timestamp-format-while-overwriting/94814>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 27, 2017, 2:28pm UTC](https://discuss.elastic.co/t/timestamp-format-while-overwriting/94814 "2017-07-27T14:28:39Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![2knarf](https://avatars.discourse-cdn.com/v4/letter/2/6a8cbe/32.png) [@2knarf](https://discuss.elastic.co/u/2knarf)\
**Post date:** [July 27, 2017, 2:28pm UTC](https://discuss.elastic.co/t/timestamp-format-while-overwriting/94814/1 "2017-07-27T14:28:39Z")

</div>

Hello, Is it possible to change the timestamp format for a logfile within filebeat?

I get this error so I need to change it.

2017-07-27T14:41:03+02:00 ERR JSON: Won't overwrite @timestamp because of parsing error: parsing time "2017-05-12T18:58:42+0000" as "2006-01-02T15:04:05Z07:00": cannot parse "+0000" as "Z07:00"

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [July 27, 2017, 3:18pm UTC](https://discuss.elastic.co/t/timestamp-format-while-overwriting/94814/2 "2017-07-27T15:18:06Z")

</div>

No, this currently not supported. Feel free to open an [enhancement request](https://github.com/elastic/beats/issues).

---

<div class="post-metadata">

**Author:** ![2knarf](https://avatars.discourse-cdn.com/v4/letter/2/6a8cbe/32.png) [@2knarf](https://discuss.elastic.co/u/2knarf)\
**Post date:** [July 28, 2017, 8:01am UTC](https://discuss.elastic.co/t/timestamp-format-while-overwriting/94814/3 "2017-07-28T08:01:21Z")

</div>

Do you have any suggestion on how I can ship the logs to Logstash with the correct timestamp?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [July 28, 2017, 1:42pm UTC](https://discuss.elastic.co/t/timestamp-format-while-overwriting/94814/4 "2017-07-28T13:42:24Z")

</div>

if you don't store the timestamp in `@timestamp`, it will be shipped as string to logstash. This will allow you to parse the timestamp in logstash.  
If you don't need multiline after json, you can also send the raw line to logstash and have logstash parse the json.

---

<div class="post-metadata">

**Author:** ![2knarf](https://avatars.discourse-cdn.com/v4/letter/2/6a8cbe/32.png) [@2knarf](https://discuss.elastic.co/u/2knarf)\
**Post date:** [August 3, 2017, 12:59pm UTC](https://discuss.elastic.co/t/timestamp-format-while-overwriting/94814/5 "2017-08-03T12:59:45Z")

</div>

Thank you for your reply, sadly it has to be sent as @timestamp due to difficulties changing the log format.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 7, 2017, 12:09pm UTC](https://discuss.elastic.co/t/timestamp-format-while-overwriting/94814/6 "2017-08-07T12:09:50Z")

</div>

If you don't store the json in the root document the `@timestamp` field is not parsed by filebeat. This allows you to post-process/parse the document via elasticsearch ingest pipeline.

New ticket: [https://github.com/elastic/beats/issues/4836](https://github.com/elastic/beats/issues/4836)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 4, 2017, 12:10pm UTC](https://discuss.elastic.co/t/timestamp-format-while-overwriting/94814/7 "2017-09-04T12:10:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
