# Use current time / system time in logstash file output?

**URL:** <https://discuss.elastic.co/t/use-current-time-system-time-in-logstash-file-output/182644>\
**Category:** Logstash\
**Created:** [May 24, 2019, 12:19pm UTC](https://discuss.elastic.co/t/use-current-time-system-time-in-logstash-file-output/182644 "2019-05-24T12:19:42Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![bjosve](https://avatars.discourse-cdn.com/v4/letter/b/ecae2f/32.png) [@bjosve](https://discuss.elastic.co/u/bjosve)\
**Post date:** [May 24, 2019, 12:19pm UTC](https://discuss.elastic.co/t/use-current-time-system-time-in-logstash-file-output/182644/1 "2019-05-24T12:19:42Z")

</div>

Hi,

Today we are using these kind of logstash file outputs,

`path => "/mnt/%{[project]}/%{[instance]}/%{[beat][hostname]}/%{[logtype]}/%{+YYYY}/%{+MM}/%{+dd}/%{[log_filename]}"`

but we can't use the date filter. We need logstash to use the current date and time. Is there any way to do this?

Best Regards,  
Bjorn

---

<div class="post-metadata">

**Author:** ![pastechecker](https://avatars.discourse-cdn.com/v4/letter/p/0ea827/32.png) [@pastechecker](https://discuss.elastic.co/u/pastechecker)\
**Post date:** [May 24, 2019, 1:13pm UTC](https://discuss.elastic.co/t/use-current-time-system-time-in-logstash-file-output/182644/2 "2019-05-24T13:13:23Z")

</div>

Hi.  
I am not sure if I am understanding your question right.  
You want the custom file name that consists with the current time of the event as it is being processed?

---

<div class="post-metadata">

**Author:** ![bjosve](https://avatars.discourse-cdn.com/v4/letter/b/ecae2f/32.png) [@bjosve](https://discuss.elastic.co/u/bjosve)\
**Post date:** [May 24, 2019, 1:33pm UTC](https://discuss.elastic.co/t/use-current-time-system-time-in-logstash-file-output/182644/3 "2019-05-24T13:33:00Z")

</div>

Hi,

> [@pastechecker](#):
>
> You want the custom file name that consists with the current time of the event as it is being processed?

I want the date / time in the custom file name to be the exact date / time when logstash writes the event to the file, nothing else. We are writing to a tamper proof area and have to use the current date / time.

---

<div class="post-metadata">

**Author:** ![logger](https://avatars.discourse-cdn.com/v4/letter/l/34f0e0/32.png) [@logger](https://discuss.elastic.co/u/logger)\
**Post date:** [May 24, 2019, 3:52pm UTC](https://discuss.elastic.co/t/use-current-time-system-time-in-logstash-file-output/182644/4 "2019-05-24T15:52:53Z")

</div>

It uses always the time from the system. so it uses the actual date and time.

why cant you use the date filter?

---

<div class="post-metadata">

**Author:** ![bjosve](https://avatars.discourse-cdn.com/v4/letter/b/ecae2f/32.png) [@bjosve](https://discuss.elastic.co/u/bjosve)\
**Post date:** [May 27, 2019, 9:03am UTC](https://discuss.elastic.co/t/use-current-time-system-time-in-logstash-file-output/182644/5 "2019-05-27T09:03:29Z")

</div>

Hi logger,

> [@logger](#):
>
> It uses always the time from the system. so it uses the actual date and time. why cant you use the date filter?

Well, not really... Read Magnus answer in this thread,

[https://discuss.elastic.co/t/add-field-timestamp-with-current-time/59862](https://discuss.elastic.co/t/add-field-timestamp-with-current-time/59862)

I will try a ruby filter.

---

<div class="post-metadata">

**Author:** ![logger](https://avatars.discourse-cdn.com/v4/letter/l/34f0e0/32.png) [@logger](https://discuss.elastic.co/u/logger)\
**Post date:** [May 27, 2019, 9:23am UTC](https://discuss.elastic.co/t/use-current-time-system-time-in-logstash-file-output/182644/6 "2019-05-27T09:23:58Z")

</div>

Ok, I thought it would be good if it uses the timestamp of the logs. so that slow processed logs will be still written to the file of the day.

Like an event which was created at 23:59:59 but will be parsed from logstash at 00:00:01 would still be saved in the file from yesterday.

If you take the ruby filter it will be saved to the new day.

---

<div class="post-metadata">

**Author:** ![bjosve](https://avatars.discourse-cdn.com/v4/letter/b/ecae2f/32.png) [@bjosve](https://discuss.elastic.co/u/bjosve)\
**Post date:** [May 27, 2019, 9:41am UTC](https://discuss.elastic.co/t/use-current-time-system-time-in-logstash-file-output/182644/7 "2019-05-27T09:41:05Z")

</div>

> [@logger](#):
>
> Ok, I thought it would be good if it uses the timestamp of the logs. so that slow processed logs will be still written to the file of the day.

I can't do that. I got to have the timestamp of the log and the file name / folder structure separated. As I wrote before, we are writing to a tamper proof area and I will get an access denied if I try to write a queued event with an "old timestamp".

---

<div class="post-metadata">

**Author:** ![logger](https://avatars.discourse-cdn.com/v4/letter/l/34f0e0/32.png) [@logger](https://discuss.elastic.co/u/logger)\
**Post date:** [May 27, 2019, 10:10am UTC](https://discuss.elastic.co/t/use-current-time-system-time-in-logstash-file-output/182644/8 "2019-05-27T10:10:35Z")

</div>

Ok, sorry. Hope it will work. 👍

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 24, 2019, 10:10am UTC](https://discuss.elastic.co/t/use-current-time-system-time-in-logstash-file-output/182644/9 "2019-06-24T10:10:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
