# Transform datetime to @timestamp

**URL:** <https://discuss.elastic.co/t/transform-datetime-to-timestamp/201062>\
**Category:** Logstash\
**Created:** [September 25, 2019, 2:26pm UTC](https://discuss.elastic.co/t/transform-datetime-to-timestamp/201062 "2019-09-25T14:26:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![fernrguez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fernrguez/32/54799_2.png) [@fernrguez](https://discuss.elastic.co/u/fernrguez)\
**Post date:** [September 25, 2019, 2:26pm UTC](https://discuss.elastic.co/t/transform-datetime-to-timestamp/201062/1 "2019-09-25T14:26:01Z")

</div>

I'm trying to use a datetime field (startTime) from the input xml logs and use it as @timestamp but something is not properly set as it idenfies the field as string but is not able to apply the transformation leaving the current time as @timestamp.

This is a sample of the date 2019-09-24T13:15:16.134+02:00

I tested with the folowing formats but none of them seems to work:

- "yyyy-MM-dd'T'HH:mm:ss'.'SSSZZ",
- "yyyy-MM-dd'T'HH:mm:ss'.'SSSZ",
- "yyyy-MM-dd'T'HH:mm:ss','SSSZZ",
- "yyyy-MM-dd'T'HH:mm:ss','SSSZ",
- "yyyy-MM-dd'T'HH:mm:ss.SSSZZ",
- "yyyy-MM-dd'T'HH:mm:ssSSSZ",
- "yyyy-MM-dd'T'HH:mm:ssSSSZZ",
- "yyyy-MM-dd'T'HH:mm:ssSSSZ"

What should be the correct format for transforming the datetime ?

```
date {
	match => ["startTime", "yyyy-MM-dd'T'HH:mm:ss'.'SSSZZ"]
}

```

Thanks in advance

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 25, 2019, 2:37pm UTC](https://discuss.elastic.co/t/transform-datetime-to-timestamp/201062/2 "2019-09-25T14:37:41Z")

</div>

```
date { match => ["ts", "YYYY-MM-dd'T'HH:mm:ss.SSSZZ"] }

```

will convert "2019-09-24T13:15:16.134+02:00" to 2019-09-24T11:15:16.134Z

---

<div class="post-metadata">

**Author:** ![fernrguez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fernrguez/32/54799_2.png) [@fernrguez](https://discuss.elastic.co/u/fernrguez)\
**Post date:** [September 25, 2019, 2:46pm UTC](https://discuss.elastic.co/t/transform-datetime-to-timestamp/201062/3 "2019-09-25T14:46:59Z")

</div>

Thanks for your quick response @Badger.

Changin the "ts" for the name of the field that has the date I have a tag _\_dateparsefailure_.

```
   filter{
       xml {
           source => "message"
           store_xml => false
           remove_namespaces => true
           xpath =>[
               "//AdapterFrameworkData","recordsList"
           ]
       }       
       split {
           field => "recordsList"
       }
       xml {
           source => "recordsList"
           store_xml => false
           remove_namespaces => true
           xpath =>[
               "//messageKey/text()","messageKey",
               "//interface/namespace/text()","namespace",
               "//interface/name/text()","name",
               "//status/text()","status",
               "//startTime/text()","startTime"
           ]
       }
	   date { match => ["startTime", "YYYY-MM-dd'T'HH:mm:ss.SSSZZ"] }	   
	   mutate
	   {
		  remove_field => ["message"]
	   }
   }
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 25, 2019, 3:10pm UTC](https://discuss.elastic.co/t/transform-datetime-to-timestamp/201062/4 "2019-09-25T15:10:55Z")

</div>

Is it an array? Does [startTime][0] work?

---

<div class="post-metadata">

**Author:** ![fernrguez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fernrguez/32/54799_2.png) [@fernrguez](https://discuss.elastic.co/u/fernrguez)\
**Post date:** [September 25, 2019, 3:22pm UTC](https://discuss.elastic.co/t/transform-datetime-to-timestamp/201062/5 "2019-09-25T15:22:00Z")

</div>

It is. I was looking into the wrong direction.

Thanks a lot.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 23, 2019, 3:22pm UTC](https://discuss.elastic.co/t/transform-datetime-to-timestamp/201062/6 "2019-10-23T15:22:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
