# Timestamp search from file

**URL:** <https://discuss.elastic.co/t/timestamp-search-from-file/257853>\
**Category:** Logstash\
**Created:** [December 7, 2020, 1:04pm UTC](https://discuss.elastic.co/t/timestamp-search-from-file/257853 "2020-12-07T13:04:47Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mihai.radulescu](https://avatars.discourse-cdn.com/v4/letter/m/a698b9/32.png) [@mihai.radulescu](https://discuss.elastic.co/u/mihai.radulescu)\
**Post date:** [December 7, 2020, 1:04pm UTC](https://discuss.elastic.co/t/timestamp-search-from-file/257853/1 "2020-12-07T13:04:48Z")

</div>

Hello,  
I have no experience with Elasticsearch, however I wish to setup an environment to be able to search through some large csv files. The import with logstash works, however I have two issues:

1. timestamp scale is using the time each record was inserted to elasticsearch, while I have a field date that is holding the decoded TimeStamp for each record from the file
2. each bar is limited at 8000 records, while in some cases I have much more

My logstash configuration is below:

```auto
input {
  file {
    path => "/mnt/xxxxxxxxxxxxx/*.txt"
    start_position => "beginning"
  }
}

filter {
      csv {
        columns => ["xx1","xx2","xx3","xx4","Responsexx","xx5","TimeStamp","Username","SourceIP"]
     }
        date {
                        match => ["TimeStamp", "yyyyMMddHHmmss"]
                        target => "date"
                        locale => "en"
                }
    }

output {
  elasticsearch {
  hosts => ["localhost:9200"]
  index => "xxxx"
  }

 }

```

Here is an image on how it looks like:

 ![elasticsearch_Mihai_1](https://us1.discourse-cdn.com/elastic/original/3X/a/8/a83039d9cc9ca9d1ee976f4335fcee3838427a33.png)

Can you help me solve these issues?

Best Regards,  
Mihai Radulescu

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 7, 2020, 1:17pm UTC](https://discuss.elastic.co/t/timestamp-search-from-file/257853/2 "2020-12-07T13:17:42Z")

</div>

It looks good. What's look like a typical line?

---

<div class="post-metadata">

**Author:** ![mihai.radulescu](https://avatars.discourse-cdn.com/v4/letter/m/a698b9/32.png) [@mihai.radulescu](https://discuss.elastic.co/u/mihai.radulescu)\
**Post date:** [December 7, 2020, 1:50pm UTC](https://discuss.elastic.co/t/timestamp-search-from-file/257853/3 "2020-12-07T13:50:38Z")

</div>

Hi dadoonet,  
I don't think it looks good enough. If you take a look at my example, the Time is "Dec 7, 2020 @ 14:37:26 129", which corresponds to the time the field was inserted and based on this one the search is done, while the timestamp/date from the record is 2020-12-07T11:41:02:000Z, which was obtained by converting the Timestamp field 20201207114102.

How can I have the Time as Timestamp or how do I configure the search to be done based on the field timestamp?

I'll check about the typical line and revert.

Best Regards,  
Mihai Radulescu

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 7, 2020, 7:45pm UTC](https://discuss.elastic.co/t/timestamp-search-from-file/257853/4 "2020-12-07T19:45:33Z")

</div>

If you want to copy the [date] field to [@timestamp] then you can do it using

```
 mutate { copy => { "date" => "@timestamp" } }

```

Alternatively, do not set the target option on the date filter and it will write the value to @timestamp to start with.

---

<div class="post-metadata">

**Author:** ![mihai.radulescu](https://avatars.discourse-cdn.com/v4/letter/m/a698b9/32.png) [@mihai.radulescu](https://discuss.elastic.co/u/mihai.radulescu)\
**Post date:** [December 9, 2020, 9:42am UTC](https://discuss.elastic.co/t/timestamp-search-from-file/257853/5 "2020-12-09T09:42:41Z")

</div>

Hi Badger,  
Removing the target option worked like a charm. Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 6, 2021, 9:42am UTC](https://discuss.elastic.co/t/timestamp-search-from-file/257853/6 "2021-01-06T09:42:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
