# Unable to ignore @timestamp in logs

**URL:** <https://discuss.elastic.co/t/unable-to-ignore-timestamp-in-logs/267141>\
**Category:** Logstash\
**Created:** [March 13, 2021, 7:40am UTC](https://discuss.elastic.co/t/unable-to-ignore-timestamp-in-logs/267141 "2021-03-13T07:40:54Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rakesh\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rakesh_b/32/48128_2.png) [@Rakesh\_B](https://discuss.elastic.co/u/Rakesh_B)\
**Post date:** [March 13, 2021, 7:40am UTC](https://discuss.elastic.co/t/unable-to-ignore-timestamp-in-logs/267141/1 "2021-03-13T07:40:54Z")

</div>

Hi,

We send multiple types of logs to Logstash and one of them uploaded JSON logs with an "@timestamp" field. Logstash tries to parse that field and when it fails it copies the value into "\_@timestamp" and throws a warning message for log event.

- We DO NOT want to parse that field, we are happy with the "\_@timestamp" field but having a warning for every event is not feasible for us. Is there a way to suppress just those warnings? (we don't want to update logging format because we will miss other essential warnings).

- I tried to rename/remove the "@timestamp" (assuming that Logstash will create a new "@timestamp" field with syslog timestamp since it is a protected field) but it didn't work and I still see logstash trying to parse the "@timestamp" from the logs. I tried the following config:

```auto
filter{
      if [log] =~ "^\{.*\}[\s\S]*$" {
        json {
          skip_on_invalid_json => true
          source => "log"
          remove_field => ["log", "@timestamp"]
        }
      }
      mutate {
        rename => {"@timestamp" => "@timestamp_orig" }
      }
}

```

Example log:

```auto
{"@message":"HTTP GET /health","@timestamp":"2021-03-13 07:05:01","@fields":{"meta":{"req":{"url":"/health","headers":{"host":"10.19.206.178:8080","user-agent":"kube-probe/1.17","accept-encoding":"gzip","connection":"close"},"method":"GET","httpVersion":"1.1","originalUrl":"/health","query":{}},"res":{"statusCode":200},"responseTime":0},"level":"info"}}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 13, 2021, 2:38pm UTC](https://discuss.elastic.co/t/unable-to-ignore-timestamp-in-logs/267141/2 "2021-03-13T14:38:20Z")

</div>

> [@Rakesh\_B](#):
>
> Is there a way to suppress just those warnings?

No, it is [unconditional](https://github.com/logstash-plugins/logstash-filter-json/blob/98f4b17d2c1ec7c72b1cc3b85392e451b2a717f9/lib/logstash/filters/json.rb#L114).

---

<div class="post-metadata">

**Author:** ![Rakesh\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rakesh_b/32/48128_2.png) [@Rakesh\_B](https://discuss.elastic.co/u/Rakesh_B)\
**Post date:** [March 13, 2021, 5:38pm UTC](https://discuss.elastic.co/t/unable-to-ignore-timestamp-in-logs/267141/3 "2021-03-13T17:38:20Z")

</div>

@Badger  
Thank you for your reply.  
Is there a way we can set the "@timestamp" to null so that it will be populated by Logstash automatically?

OR parsing the timestamp is the ONLY option for us? The reason why we don't want to parse the "@timestamp" is because there is a good chance that another application in the future will have a new format of "@timestamp" and then we will be back to square one.

- Thank you

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 13, 2021, 7:02pm UTC](https://discuss.elastic.co/t/unable-to-ignore-timestamp-in-logs/267141/4 "2021-03-13T19:02:46Z")

</div>

You can use mutate+remove\_field to remove the default @timestamp field, then set it to the current time using the configuration from [this](https://discuss.elastic.co/t/how-can-i-set-current-time-in-field/157542) thread.

---

<div class="post-metadata">

**Author:** ![Rakesh\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rakesh_b/32/48128_2.png) [@Rakesh\_B](https://discuss.elastic.co/u/Rakesh_B)\
**Post date:** [March 14, 2021, 7:28pm UTC](https://discuss.elastic.co/t/unable-to-ignore-timestamp-in-logs/267141/5 "2021-03-14T19:28:36Z")

</div>

@Badger  
I tried the following but still no luck

```auto
      mutate {
        remove_field => ["@timestamp"]
      }
      ruby {
        code => "event.set('logstash_processed_at', Time.now());"
      }
      mutate {
        convert => { "logstash_processed_at" => "string" }
      }
      date {
        match => ["logstash_processed_at", "ISO8601"]
        target => "@timestamp"
        add_tag => "timestamp_changed"
      }

```

In the logs I do see

```auto
logstash_processed_at: 2021-03-14T19:17:20.364Z

```

- Thank you

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 14, 2021, 9:51pm UTC](https://discuss.elastic.co/t/unable-to-ignore-timestamp-in-logs/267141/6 "2021-03-14T21:51:32Z")

</div>

> [@Rakesh\_B](#):
>
> I tried the following but still no luck

I don't know what to say -- that code works for me.

---

<div class="post-metadata">

**Author:** ![Rakesh\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rakesh_b/32/48128_2.png) [@Rakesh\_B](https://discuss.elastic.co/u/Rakesh_B)\
**Post date:** [March 15, 2021, 4:22pm UTC](https://discuss.elastic.co/t/unable-to-ignore-timestamp-in-logs/267141/7 "2021-03-15T16:22:59Z")

</div>

I figured out the issue, the problem was that since I used the JSON filter, it automatically parses the "@timestamp" and throws the warning. I had to get a little bit creative like this:

```auto
      if [log] =~ "^\{.*\}[\s\S]*$" {
        json {
          skip_on_invalid_json => true
          source => "log"
          target => "log_json"
        }
      }
      if [log_json][@timestamp] {
        mutate {
          remove_field => "[log_json][@timestamp]"
        }
      }
      if [log_json] {
        json {
          skip_on_invalid_json => true
          source => "log_json"
        }
      }
      if [log_json] {
        ruby {
            code => '
                event.get("log_json").each { |k, v|
                    event.set(k,v)
                }
                event.remove("log_json")
            '
        }
      }

```

Thanks for all your help 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2021, 4:23pm UTC](https://discuss.elastic.co/t/unable-to-ignore-timestamp-in-logs/267141/8 "2021-04-12T16:23:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
