# Timestamp warnings in elasticsearch logs

**URL:** <https://discuss.elastic.co/t/timestamp-warnings-in-elasticsearch-logs/156504>\
**Category:** Elasticsearch\
**Created:** [November 13, 2018, 3:08pm UTC](https://discuss.elastic.co/t/timestamp-warnings-in-elasticsearch-logs/156504 "2018-11-13T15:08:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Maddy\_M](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maddy_m/32/45638_2.png) [@Maddy\_M](https://discuss.elastic.co/u/Maddy_M)\
**Post date:** [November 13, 2018, 3:08pm UTC](https://discuss.elastic.co/t/timestamp-warnings-in-elasticsearch-logs/156504/1 "2018-11-13T15:08:40Z")

</div>

Hi,

I see following exception es.deprecation.log. I see that this question was answered earlier other thread, but, it has less explanation.

> [@Elastic Search 6.4.0 log file filling up the with WARNing messages](https://discuss.elastic.co/t/elastic-search-6-4-0-log-file-filling-up-the-with-warning-messages/151081):
>
> ELASTICSEARCH\_VERSION=6.4.0 [2018-10-04T16:25:14,539][WARN][o.e.d.s.f.s.DocValueFieldsFetchSubPhase] Doc-value field [@timestamp] is not using a format. The output will change in 7.0 when doc value fields get formatted based on mappings by default. It is recommended to pass [format=use\_field\_mapping] with the doc value field in order to opt in for the future behaviour and ease the migration to 7.0. I updated the template for date fields to have format. But I still see those warnings in the lo…

[WARN][o.e.d.s.f.s.DocValueFieldsFetchSubPhase] Doc-value field [@timestamp] is not using a format. The output will change in 7.0 when doc value fields get formatted based on mappings by default. It is recommended to pass [format=use\_field\_mapping] with the doc value field in order to opt in for the future behaviour and ease the migration to 7.0.

1. I was trying to understand, what format of timestamp we need to use to write to elasticsearch to avoid this issue ?
2. Earlier post suggests that to suppress the warnings, but I was trying to format the date.

Could you please advise on this?

Thanks,  
Maddy

---

<div class="post-metadata">

**Author:** ![Maddy\_M](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maddy_m/32/45638_2.png) [@Maddy\_M](https://discuss.elastic.co/u/Maddy_M)\
**Post date:** [November 14, 2018, 2:27pm UTC](https://discuss.elastic.co/t/timestamp-warnings-in-elasticsearch-logs/156504/2 "2018-11-14T14:27:45Z")

</div>

Any help on this?

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [November 14, 2018, 3:13pm UTC](https://discuss.elastic.co/t/timestamp-warnings-in-elasticsearch-logs/156504/3 "2018-11-14T15:13:28Z")

</div>

> [@Maddy\_M](#):
>
> I was trying to understand, what format of timestamp we need to use to write to elasticsearch to avoid this issue ?

This warning is generated by searches, not by writing to Elasticsearch. The fix is to be explicit about the timestamp format in searches, because the behaviour will change in 7.0 and this might break your application.

---

<div class="post-metadata">

**Author:** ![Maddy\_M](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maddy_m/32/45638_2.png) [@Maddy\_M](https://discuss.elastic.co/u/Maddy_M)\
**Post date:** [November 20, 2018, 6:23pm UTC](https://discuss.elastic.co/t/timestamp-warnings-in-elasticsearch-logs/156504/4 "2018-11-20T18:23:12Z")

</div>

Thanks for the update. In this case, kibana is making search.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 18, 2018, 6:23pm UTC](https://discuss.elastic.co/t/timestamp-warnings-in-elasticsearch-logs/156504/5 "2018-12-18T18:23:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
