# Unable to replace @timestamp with some other field in logstash

**URL:** <https://discuss.elastic.co/t/unable-to-replace-timestamp-with-some-other-field-in-logstash/97425>\
**Category:** Logstash\
**Created:** [August 17, 2017, 1:28pm UTC](https://discuss.elastic.co/t/unable-to-replace-timestamp-with-some-other-field-in-logstash/97425 "2017-08-17T13:28:01Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![shraddha1](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@shraddha1](https://discuss.elastic.co/u/shraddha1)\
**Post date:** [August 17, 2017, 1:28pm UTC](https://discuss.elastic.co/t/unable-to-replace-timestamp-with-some-other-field-in-logstash/97425/1 "2017-08-17T13:28:01Z")

</div>

I want to map @timestamp value with some other field. I referred your answers online but could not resolve the issue.

I have converted string to date and want this date to be reflected in @timestamp. but no luck.

Below is the filter condition

filter {  
if [type] == “syslog” {  
grok {  
match =\> { “message” =\> “%{SYSLOGLINE}” }  
}  
mutate {  
split =\> { “message” =\> “~” }  
add\_field =\> {“QueueManagerName” =\> “%{message[0]}”}  
add\_field =\> {“Date” =\> “%{message[1]}”}  
add\_field =\> {“Time” =\> “%{message[2]}”}  
add\_field =\> {“hh:mm” =\> “%{message[3]}”}  
add\_field =\> {“Shift” =\> “%{message[4]}”}  
add\_field =\> {“Queue” =\> “%{message[5]}”}  
add\_field =\> {“maxDepth” =\> “%{message[6]}”}  
add\_field =\> {“P\_Put” =\> “%{message[10]}”}  
add\_field =\> {“Get\_P” =\> “%{message[14}”}  
add\_field =\> {“timestamp” =\> “%{Date} %{Time}”}  
}  
date {  
target =\> "timestamp"  
match =\> [“timestamp”, “yyyy-MM-dd HH:mm:ss”, “ISO8601”]  
timezone =\> “UTC”  
}  
}  
}

The message in the logfile is separated by ~ so used split to assign each value in different fields.

timestamp and @timestamp does not have same value

timestamp contains value from log but @timetsamp sets to current time

Can you please help to figure out the issue.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 17, 2017, 7:40pm UTC](https://discuss.elastic.co/t/unable-to-replace-timestamp-with-some-other-field-in-logstash/97425/2 "2017-08-17T19:40:01Z")

</div>

Please show us an example event. Use a `stdout { codec => rubydebug }` output.

> timestamp and @timestamp does not have same value

Why would they have the same value when you've configured the date filter to store the parsed timestamp into the `timestamp` field, leaving `@timestamp` untouched?

---

<div class="post-metadata">

**Author:** ![shraddha1](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@shraddha1](https://discuss.elastic.co/u/shraddha1)\
**Post date:** [August 18, 2017, 3:13pm UTC](https://discuss.elastic.co/t/unable-to-replace-timestamp-with-some-other-field-in-logstash/97425/3 "2017-08-18T15:13:47Z")

</div>

Hi,  
Thanks. I have changed the code and adding the new calculated datetime value in a new field called eventtimestamp leaving @timestamp alone.

under mutate i have added below line

add\_field =\> {"eventtimetsamp" =\> "%{Date} %{Time}"}

and below is my date code

date {  
target =\> "eventtimestamp"  
match =\> ["eventtimestamp", "yyyy-MM-dd HH:mm:ss.sssZ", "ISO8601"]  
timezone =\> "UTC"  
}

Now, the expectation is this new field will be a date field that I can use in Kibana, but this field is coming as string. Can you please take a look at my code and tell me what I am doing wrong here?

---

<div class="post-metadata">

**Author:** ![shraddha1](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@shraddha1](https://discuss.elastic.co/u/shraddha1)\
**Post date:** [August 18, 2017, 3:15pm UTC](https://discuss.elastic.co/t/unable-to-replace-timestamp-with-some-other-field-in-logstash/97425/4 "2017-08-18T15:15:45Z")

</div>

Also the output plugin code is  
output {  
elasticsearch {  
hosts =\> “:9200” index =\> “logstash-%{+YYYY.MM.dd}” user =\> “logstash\_user” password =\> “”  
}  
stdout {codec =\> rubydebug}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 20, 2017, 6:24pm UTC](https://discuss.elastic.co/t/unable-to-replace-timestamp-with-some-other-field-in-logstash/97425/5 "2017-08-20T18:24:38Z")

</div>

> Now, the expectation is this new field will be a date field that I can use in Kibana, but this field is coming as string. Can you please take a look at my code and tell me what I am doing wrong here?

Is the date filter successful? What does an event look like? What probably happened here is that you sent a document to ES with a `eventtimestamp` value not being parseable as a date, so it was mapped as a string. Since the mapping of a field can't be changed after the fact for a particular index it made no difference that subsequent documents may have had `eventtimestamp` fields that would've been recognized as dates. Unless you have precious data in the index just delete it and run Logstash again to index new data.

This is another reason why it's a good idea to only enable the elasticsearch output once you've verified with e.g. a stdout output that things are working.

---

<div class="post-metadata">

**Author:** ![shraddha1](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@shraddha1](https://discuss.elastic.co/u/shraddha1)\
**Post date:** [August 22, 2017, 2:08pm UTC](https://discuss.elastic.co/t/unable-to-replace-timestamp-with-some-other-field-in-logstash/97425/6 "2017-08-22T14:08:36Z")

</div>

Thanks. It worked by updating the index

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 19, 2017, 2:08pm UTC](https://discuss.elastic.co/t/unable-to-replace-timestamp-with-some-other-field-in-logstash/97425/7 "2017-09-19T14:08:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
