# Using event API for timestamp formatting

**URL:** <https://discuss.elastic.co/t/using-event-api-for-timestamp-formatting/85374>\
**Category:** Logstash\
**Created:** [May 11, 2017, 11:08am UTC](https://discuss.elastic.co/t/using-event-api-for-timestamp-formatting/85374 "2017-05-11T11:08:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![arnold79](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arnold79/32/141473_2.png) [@arnold79](https://discuss.elastic.co/u/arnold79)\
**Post date:** [May 11, 2017, 11:08am UTC](https://discuss.elastic.co/t/using-event-api-for-timestamp-formatting/85374/1 "2017-05-11T11:08:09Z")

</div>

Hi all,

I need to escalate events towards a separate output. The events are received in UTC timezone and need to be converted to Europe/Amsterdam. I've created a date filter to add additional two hours and ruby filter to put it back in the correct format. But I' can't get it working 😭

I have the following code and tried the following configs. Inspired on the event API documentation, but better ideas are welcome .

Tried various options like event.sprintf, event.get with %{MMM dd HH:mm:ss} variable and even .strftime.  
Below a the code that isn' working.

```
    filter {
      date {
        locale=> "en"
        match => ["timestamp", "MMM dd HH:mm:ss"]
        timezone => "Etc/GMT+2"
      }
      
      ruby {
       #code=> "event['localtimestamp'] = event.sprintf('%{MMM dd HH:mm:ss}')"
    #code => "event.set('localtimestamp', event.sprintf(%{MMM dd HH:mm:ss}))"
    #code => "event.set('localtimestamp', event.get('%{MMM dd HH:mm:ss}'))"
    code => "event.set('localtimestamp', event.get(%{MMM dd HH:mm:ss}))"
   #code => "event.set('localtimestamp', event.get('@timestamp').strftime('%Y-%m-%d_%H-%M-%S'))"
      }
    }

```

Does anyone has an idea to convert the time from UTC to Europe/Amsterdam fully or partly ( only formatting) with Ruby filter + event API usage ?

---

<div class="post-metadata">

**Author:** ![arnold79](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arnold79/32/141473_2.png) [@arnold79](https://discuss.elastic.co/u/arnold79)\
**Post date:** [May 11, 2017, 11:59am UTC](https://discuss.elastic.co/t/using-event-api-for-timestamp-formatting/85374/2 "2017-05-11T11:59:21Z")

</div>

> [@arnold79](#):
>
> strftim

I can say that the Ruby part of formatting is now almost working with following code (as string). I will update some new updates . Still curious how you guys are doing this !!

ruby {

```
code => "tstamp = event.get('@timestamp').to_i
        event.set('blaat', Time.at(tstamp).strftime('%Y-%m-%d %H:%M:%S'))"

```

}

---

<div class="post-metadata">

**Author:** ![Nico-DF](https://avatars.discourse-cdn.com/v4/letter/n/ed8c4c/32.png) [@Nico-DF](https://discuss.elastic.co/u/Nico-DF)\
**Post date:** [May 11, 2017, 12:01pm UTC](https://discuss.elastic.co/t/using-event-api-for-timestamp-formatting/85374/3 "2017-05-11T12:01:33Z")

</div>

Maybe you can create Time object directly if you have access to all timestamp fields

```auto
Time.new(event.get('year'), ...)

```

---

<div class="post-metadata">

**Author:** ![arnold79](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arnold79/32/141473_2.png) [@arnold79](https://discuss.elastic.co/u/arnold79)\
**Post date:** [May 17, 2017, 2:53pm UTC](https://discuss.elastic.co/t/using-event-api-for-timestamp-formatting/85374/4 "2017-05-17T14:53:30Z")

</div>

HI @nico-DF,

thanks for your help.

I've got it working with the following config ( using a linux logstash agent with default europe/amsterdam timezone configured:

_First get seconds from UTC timestamp and then format a string in our required timezone and syslog format using the Time lib._

> filter {  
> date {  
> match =\> ["timestamp", "MMM dd HH:mm:ss"]  
> timezone =\> "UTC"  
> }
> 
> ruby {  
> code =\> "tstamp = event.get('@timestamp').to\_i  
> event.set('epoch',tstamp)  
> event.set('syslogtime', Time.at(tstamp).strftime('%b %e %H:%M:%S'))"  
> }  
> }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2017, 2:53pm UTC](https://discuss.elastic.co/t/using-event-api-for-timestamp-formatting/85374/5 "2017-06-14T14:53:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
