# Timestamp problem created using dissect

**URL:** <https://discuss.elastic.co/t/timestamp-problem-created-using-dissect/157782>\
**Category:** Logstash\
**Created:** [November 21, 2018, 10:06pm UTC](https://discuss.elastic.co/t/timestamp-problem-created-using-dissect/157782 "2018-11-21T22:06:51Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![RussellBateman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/russellbateman/32/34928_2.png) [@RussellBateman](https://discuss.elastic.co/u/RussellBateman)\
**Post date:** [November 21, 2018, 10:06pm UTC](https://discuss.elastic.co/t/timestamp-problem-created-using-dissect/157782/1 "2018-11-21T22:06:51Z")

</div>

I have this filter which works very well except for mucking up the date in dissection. (What's in the ellipsis below, ..., is too long and everything is working anyway.)

```
filter
{
  dissect
  {
    "message" => "%{acme.date} %{acme.time} CEF:%{acme.version}|...
  }
}

```

operating on data like this:

`message: 2018-11-08 21:57:37,208 CEF:0|...`

and it creates these fields:

```
acme.date: November 7th 2018, 17:00:00.000
acme.time: 21:57:37,208
acme.version: 0

```

I don't know where the `, 17:00:00,000` comes from, but I don't want it and I would prefer that `acme.date` contain `2018-11-08` in the end. (`acme.time` and `acme.version` are perfect.)

---

_[View the full topic](https://discuss.elastic.co/t/timestamp-problem-created-using-dissect/157782)._
