# @timestamp is missing in Time-field name in Logstash template

**URL:** <https://discuss.elastic.co/t/timestamp-is-missing-in-time-field-name-in-logstash-template/77187>\
**Category:** Logstash\
**Created:** [March 2, 2017, 5:01pm UTC](https://discuss.elastic.co/t/timestamp-is-missing-in-time-field-name-in-logstash-template/77187 "2017-03-02T17:01:39Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![111148](https://avatars.discourse-cdn.com/v4/letter/1/eb8c5e/32.png) [@111148](https://discuss.elastic.co/u/111148)\
**Post date:** [March 2, 2017, 5:01pm UTC](https://discuss.elastic.co/t/timestamp-is-missing-in-time-field-name-in-logstash-template/77187/1 "2017-03-02T17:01:39Z")

</div>

Hello, i am using this default template from logstash 5.2. folder in order to create it in Kibana for elastic search.

{  
"template" : "logstash-_",  
"version" : 50001,  
"settings" : {  
"index.refresh\_interval" : "5s"  
},  
"mappings" : {  
"default" : {  
"\_all" : {"enabled" : true, "norms" : false},  
"dynamic\_templates" : [ {  
"message\_field" : {  
"path\_match" : "message",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "text",  
"norms" : false  
}  
}  
}, {  
"string\_fields" : {  
"match" : "_",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "text", "norms" : false,  
"fields" : {  
"keyword" : { "type": "keyword" }  
}  
}  
}  
} ],  
"properties" : {  
"@timestamp": { "type": "date", "include\_in\_all": false },  
"@version": { "type": "keyword", "include\_in\_all": false },  
"geoip" : {  
"dynamic": true,  
"properties" : {  
"ip": { "type": "ip" },  
"location" : { "type" : "geo\_point" },  
"latitude" : { "type" : "half\_float" },  
"longitude" : { "type" : "half\_float" }  
}  
}  
}  
}  
}  
}

But after it is done i can not see the @timestamp or time field on the node.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/f/0/f012158a2c34bcc29999852fb62666cabb83cb11.png)

Please advise what i am doing wrong.

I have deleted old index with proper logstash template parameters accidentally and now i can not create second one. Please advise how to do it properly so as reading manuals is not rather informative for me). Thanks.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 3, 2017, 11:17am UTC](https://discuss.elastic.co/t/timestamp-is-missing-in-time-field-name-in-logstash-template/77187/2 "2017-03-03T11:17:05Z")

</div>

Do you have any index created that match that index pattern? I believe Kibana looks for mappings for indices that match the pattern, not index templates that will match once an index is created.

---

<div class="post-metadata">

**Author:** ![111148](https://avatars.discourse-cdn.com/v4/letter/1/eb8c5e/32.png) [@111148](https://discuss.elastic.co/u/111148)\
**Post date:** [March 3, 2017, 11:51am UTC](https://discuss.elastic.co/t/timestamp-is-missing-in-time-field-name-in-logstash-template/77187/3 "2017-03-03T11:51:07Z")

</div>

Hello Christian,  
Thanks for your answer.  
I was forced delete logstash and install it from scratch so as i was not able to solve this issue with recreating an index. But only managed to do it only from the 3-d attempt. Logstash can not load template successfully from time to time to Elastic.  
in order to overcome this i was forced shutdown the rest 2 of 3 nodes in ELK cluster and only then i have managed to load template with existing index to Logstash. But honestly saying i still do not understand how it works and how it should work normally.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 3, 2017, 11:52am UTC](https://discuss.elastic.co/t/timestamp-is-missing-in-time-field-name-in-logstash-template/77187/4 "2017-03-03T11:52:18Z")

</div>

Is there anything in the Elasticsearch logs?

---

<div class="post-metadata">

**Author:** ![111148](https://avatars.discourse-cdn.com/v4/letter/1/eb8c5e/32.png) [@111148](https://discuss.elastic.co/u/111148)\
**Post date:** [March 3, 2017, 12:04pm UTC](https://discuss.elastic.co/t/timestamp-is-missing-in-time-field-name-in-logstash-template/77187/5 "2017-03-03T12:04:20Z")

</div>

Nothing suspicious except json parse errors:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/a/4/a4467cf23cf1d7eb1df463a2750a24f176feadb0.png)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 3, 2017, 12:05pm UTC](https://discuss.elastic.co/t/timestamp-is-missing-in-time-field-name-in-logstash-template/77187/6 "2017-03-03T12:05:32Z")

</div>

That seems to be from the Logstash log, not Elasticsearch.

---

<div class="post-metadata">

**Author:** ![111148](https://avatars.discourse-cdn.com/v4/letter/1/eb8c5e/32.png) [@111148](https://discuss.elastic.co/u/111148)\
**Post date:** [March 3, 2017, 12:07pm UTC](https://discuss.elastic.co/t/timestamp-is-missing-in-time-field-name-in-logstash-template/77187/7 "2017-03-03T12:07:14Z")

</div>

Sorry. Yes.  
But i though it is related to Logstash problem so as i am now in Logstash forum.  
Checking the Elastic logs.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 3, 2017, 12:09pm UTC](https://discuss.elastic.co/t/timestamp-is-missing-in-time-field-name-in-logstash-template/77187/8 "2017-03-03T12:09:39Z")

</div>

The JSON conversion issue is Logstash, but that is what you opened a separate issue about. I was wondering about logs related to the issue around creating an index.

If that is no longer an issue we can leave it.

---

<div class="post-metadata">

**Author:** ![111148](https://avatars.discourse-cdn.com/v4/letter/1/eb8c5e/32.png) [@111148](https://discuss.elastic.co/u/111148)\
**Post date:** [March 3, 2017, 12:23pm UTC](https://discuss.elastic.co/t/timestamp-is-missing-in-time-field-name-in-logstash-template/77187/9 "2017-03-03T12:23:28Z")

</div>

In Elastic logs i see only error about "index can not be imported"

 ![](https://us1.discourse-cdn.com/elastic/original/3X/5/b/5bdd78f63587851d22686fc29afcfb140890674c.png)

---

<div class="post-metadata">

**Author:** ![111148](https://avatars.discourse-cdn.com/v4/letter/1/eb8c5e/32.png) [@111148](https://discuss.elastic.co/u/111148)\
**Post date:** [March 6, 2017, 5:32pm UTC](https://discuss.elastic.co/t/timestamp-is-missing-in-time-field-name-in-logstash-template/77187/10 "2017-03-06T17:32:06Z")

</div>

Hello,  
Again facing with this issue. Looks like your default template does not work as expected in Dev tools and in CURL as well.  
Could you please try on your side and check if issue is reproducible?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2017, 5:32pm UTC](https://discuss.elastic.co/t/timestamp-is-missing-in-time-field-name-in-logstash-template/77187/11 "2017-04-03T17:32:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
