# @timestamp is not matching the actual event time from the router syslog

**URL:** <https://discuss.elastic.co/t/timestamp-is-not-matching-the-actual-event-time-from-the-router-syslog/163163>\
**Category:** Logstash\
**Created:** [January 7, 2019, 8:00am UTC](https://discuss.elastic.co/t/timestamp-is-not-matching-the-actual-event-time-from-the-router-syslog/163163 "2019-01-07T08:00:49Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![ajayraghuraj](https://avatars.discourse-cdn.com/v4/letter/a/e68b1a/32.png) [@ajayraghuraj](https://discuss.elastic.co/u/ajayraghuraj)\
**Post date:** [January 7, 2019, 8:00am UTC](https://discuss.elastic.co/t/timestamp-is-not-matching-the-actual-event-time-from-the-router-syslog/163163/1 "2019-01-07T08:00:49Z")

</div>

elasticsearch is creating indexes with a future date. @timestamp is not matching the actual event time from the router syslog . The actual event time is Nov 30 2018. Could anyone tell me why the index and @timestamp is not 2018 ?

"Nov 30 10:40:16 system-aaaaaa 172: \*Nov 30 01:49:00.001: %PARSER-5-CFGLOG\_LOGGEDCMD: User:admin logged command:router bgp 65008"

"filebeat-6.2.4-2019.11.30"

content of one of the documents

```
  {
    "_index": "filebeat-6.2.4-2019.11.30",
    "_type": "doc",
    "_id": "_sZBJ2gBAn3SQNgAVupJ",
    "_score": 1,
    "_source": {
      "offset": 56292,
      "beat": {
        "hostname": "xxx-xxxx-02",
        "version": "6.2.4",
        "name": "xxx-xxxx-02"
      },
      "@timestamp": "2019-11-30T02:40:16.000Z",
      "tags": [
        "beats_input_codec_plain_applied"
      ],
      "prospector": {
        "type": "log"
      },
      "source": "/var/log/HOSTS/system-aaaaaa.log-20190106",
      "system": {
        "syslog": {
          "hostname": "system-aaaaaa",
          "message": "*Nov 30 01:49:00.001: %PARSER-5-CFGLOG_LOGGEDCMD: User:admin logged command:router bgp 65008 ",
          "program": "172",
          "timestamp": "Nov 30 10:40:16"
        }
      },
      "host": "xxx-xxxx-02",
      "@version": "1",
      "fileset": {
        "module": "system",
        "name": "syslog"
      }
    }

```

this is my logstash configuration.

input {  
beats {  
port =\> 5044  
host =\> "0.0.0.0"  
}  
}  
filter {  
if [fileset][module] == "system" {  
if [fileset][name] == "syslog" {  
grok {  
match =\> { "message" =\> ["%{SYSLOGTIMESTAMP:[system][syslog][timestamp]} %{SYSLOGHOST:[system][syslog][hostname]} %{DATA:[system][syslog][program]}(?:[%{POSINT:[system][syslog][pid]}])?: %{GREEDYMULTILINE:[system][syslog][message]}"] }  
pattern\_definitions =\> { "GREEDYMULTILINE" =\> "(.|\n)\*" }  
remove\_field =\> "message"  
}  
date {  
match =\> ["[system][syslog][timestamp]", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]  
}  
}  
}  
}  
output {  
elasticsearch {  
user =\> logstash\_system  
password =\> xxxxxxx  
hosts =\> ["es-host:3306"]  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 7, 2019, 8:03am UTC](https://discuss.elastic.co/t/timestamp-is-not-matching-the-actual-event-time-from-the-router-syslog/163163/2 "2019-01-07T08:03:11Z")

</div>

Because Logstash assumes that the missing year in the timestamp is this year.

Not sure how to resolve that though sorry.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 7, 2019, 8:37am UTC](https://discuss.elastic.co/t/timestamp-is-not-matching-the-actual-event-time-from-the-router-syslog/163163/3 "2019-01-07T08:37:35Z")

</div>

If you assume the date can not be in the future, you may able to do something like this:

```auto
input {
  generator {
    lines => ['Jan 01 01:49:00.001',
              'Nov 30 01:49:00.001']
    count => 1
  } 
} 

filter {
  date {
    match => ["message", "MMM d HH:mm:ss.SSS", "MMM dd HH:mm:ss.SSS"]
    target=> "[@metadata][tmpdate]"
  }

  if [@metadata][tmpdate] > [@timestamp] {
    mutate {
      add_field => { "[@metadata][fulltmpdate]" => "2018 %{[message}"}
    }

    date {
      match => ["[@metadata][fulltmpdate]", "yyyy MMM d HH:mm:ss.SSS", "yyyy MMM dd HH:mm:ss.SSS" ]
    }
  } else {
    date {
      match => ["message", "MMM d HH:mm:ss.SSS", "MMM dd HH:mm:ss.SSS"]
    }
  }
}

output {
  stdout { codec => rubydebug { metadata => true} }
}

```

Adapt the fields to fit your data structure.

---

<div class="post-metadata">

**Author:** ![ajayraghuraj](https://avatars.discourse-cdn.com/v4/letter/a/e68b1a/32.png) [@ajayraghuraj](https://discuss.elastic.co/u/ajayraghuraj)\
**Post date:** [January 9, 2019, 2:22am UTC](https://discuss.elastic.co/t/timestamp-is-not-matching-the-actual-event-time-from-the-router-syslog/163163/4 "2019-01-09T02:22:45Z")

</div>

but according to the change log, as of version 2.1.0 the year rollover is handled internally. i should not be seeing this behaviour. can you clarify ?

# /usr/share/logstash/bin/logstash-plugin list --verbose |grep input

logstash-filter-date (3.1.9)

> <https://github.com/logstash-plugins/logstash-filter-date/blob/v3.1.9/CHANGELOG.md>

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 9, 2019, 3:46am UTC](https://discuss.elastic.co/t/timestamp-is-not-matching-the-actual-event-time-from-the-router-syslog/163163/5 "2019-01-09T03:46:55Z")

</div>

It might be a regression then, can you raise an issue under the plugin so we can dig into it?

---

<div class="post-metadata">

**Author:** ![ajayraghuraj](https://avatars.discourse-cdn.com/v4/letter/a/e68b1a/32.png) [@ajayraghuraj](https://discuss.elastic.co/u/ajayraghuraj)\
**Post date:** [January 9, 2019, 5:46am UTC](https://discuss.elastic.co/t/timestamp-is-not-matching-the-actual-event-time-from-the-router-syslog/163163/6 "2019-01-09T05:46:29Z")

</div>

made the changes to the logstash configurations per recommendation from Christian. I will monitor it for sometime. thanks

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 9, 2019, 7:27am UTC](https://discuss.elastic.co/t/timestamp-is-not-matching-the-actual-event-time-from-the-router-syslog/163163/7 "2019-01-09T07:27:29Z")

</div>

The change you pointed to only seems to handle the rollover between December and January. As your data belongs to November and comes over a month late, it is not caught by this fix.

---

<div class="post-metadata">

**Author:** ![ajayraghuraj](https://avatars.discourse-cdn.com/v4/letter/a/e68b1a/32.png) [@ajayraghuraj](https://discuss.elastic.co/u/ajayraghuraj)\
**Post date:** [January 9, 2019, 8:19am UTC](https://discuss.elastic.co/t/timestamp-is-not-matching-the-actual-event-time-from-the-router-syslog/163163/8 "2019-01-09T08:19:43Z")

</div>

Christian, are you talking about how logstash handles the rollover ?

i am monitoring the data after apply the recommendations to the logstash configuration . seems to be working fine. i can see all date from 2018 with the correct timestamp now.

what happens when we roll over to 2020 ? are we going to face a similar problem ?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 9, 2019, 8:23am UTC](https://discuss.elastic.co/t/timestamp-is-not-matching-the-actual-event-time-from-the-router-syslog/163163/9 "2019-01-09T08:23:03Z")

</div>

If data does not arrive delayed more than a month I suspect the fix you linked to will handle it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 6, 2019, 8:23am UTC](https://discuss.elastic.co/t/timestamp-is-not-matching-the-actual-event-time-from-the-router-syslog/163163/10 "2019-02-06T08:23:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
