# What is @timestamp field exactly?

**URL:** <https://discuss.elastic.co/t/what-is-timestamp-field-exactly/277189>\
**Category:** APM\
**Tags:** server, ui\
**Created:** [June 28, 2021, 9:21am UTC](https://discuss.elastic.co/t/what-is-timestamp-field-exactly/277189 "2021-06-28T09:21:23Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ebuildy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebuildy/32/6070_2.png) [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Post date:** [June 28, 2021, 9:21am UTC](https://discuss.elastic.co/t/what-is-timestamp-field-exactly/277189/1 "2021-06-28T09:21:23Z")

</div>

**Kibana version** : 7.13.2

**Elasticsearch version** : 7.13.2

**APM Server version** : 7.13.2

**APM Agent language and version** : nodeJS / RUM

We run a very busy web site, with continuous traffic, but as you can see from the image below:

 ![Capture d’écran 2021-06-28 à 11.18.49](https://us1.discourse-cdn.com/elastic/original/3X/7/2/7264b70ef361cec4ede9f11b15aa3dbdf95fd3a9.png)

We receive data by batch,

it looks like @timestamp field is the time elasticsearch index the data?  
Or this represent the time apm-server receive the event?

This give us totally wrong data-viz on APM dashboard:

 ![Capture d’écran 2021-06-28 à 12.06.10](https://us1.discourse-cdn.com/elastic/original/3X/1/5/159d0f4bfa382e580bedd4b30c8810f75ac428ed.png)

Should I disable "transaction metrics" feature?

Our `apm-server.yaml`:

```auto
apm-server:
  # https://www.elastic.co/guide/en/apm/server/7.13/transaction-metrics.html
  aggregation:
    transactions:
      enabled: true
      interval: 1m
      max_groups: 5000
  sampling:
    keep_unsampled: true
  queue:
    mem.events: 10096
    flush.timeout: 5s
    flush.min_events: 50
  max_procs: 4
output:
  file:
    enabled: false
  elasticsearch:
    enabled: true
    hosts: ["XXXXXXX"]
    bulk_max_size: 750
    worker: 4
    max_retries: 0
    username: "${ELASTICSEARCH_USERNAME}"
    password: "${ELASTICSEARCH_PASSWORD}"
    timeout: 10
    ssl:
      enabled: true
      verification_mode: certificate
      certificate_authorities:
      - /usr/share/infra/datahub/certs/ca.crt
    backoff:
      init: 1s
      max: 30s
    pipelines:
    - pipeline: "apm_user_agent"
    - pipeline: "apm_ingest_timestamp"
    - pipeline: "apm_remove_span_metadata"

```

`kibana.yaml`

```auto
xpack.apm:
            enabled: true
            searchAggregatedTransactions: always

```

---

<div class="post-metadata">

**Author:** ![sqren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sqren/32/26110_2.png) [@sqren](https://discuss.elastic.co/u/sqren)\
**Post date:** [June 29, 2021, 9:06am UTC](https://discuss.elastic.co/t/what-is-timestamp-field-exactly/277189/2 "2021-06-29T09:06:38Z")

</div>

Hi there,

> it looks like @timestamp field is the time elasticsearch index the data?  
> Or this represent the time apm-server receive the event?

`@timestamp` is recorded by the APM agent when the event happens. There is also `event.ingested` which is created by an ingest pipeline upon arrival in Elasticsearch.

> This give us totally wrong data-viz on APM dashboard:

Yes, it looks odd when "zooming in" since metrics are indexed in batches every minute. If you choose a larger time range this should not be a problem though.

> Should I disable "transaction metrics" feature?

If you don't want to use metrics you can disable this, yes. But I'm curious whether you have enabled this in Kibana also? By default Kibana will use transactions instead of metrics, unless this setting has been modified:

```auto
xpack.apm.searchAggregatedTransactions: 'never'

```

`never` is the default. Changing it to `always` or `auto` will make Kibana prefer metrics over transactions.

---

<div class="post-metadata">

**Author:** ![sqren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sqren/32/26110_2.png) [@sqren](https://discuss.elastic.co/u/sqren)\
**Post date:** [June 29, 2021, 11:05am UTC](https://discuss.elastic.co/t/what-is-timestamp-field-exactly/277189/3 "2021-06-29T11:05:58Z")

</div>

Sorry, one correction: For metric documents `@timestamp` will be set by the APM Server - not by the APM agent.

---

<div class="post-metadata">

**Author:** ![sqren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sqren/32/26110_2.png) [@sqren](https://discuss.elastic.co/u/sqren)\
**Post date:** [June 29, 2021, 1:36pm UTC](https://discuss.elastic.co/t/what-is-timestamp-field-exactly/277189/4 "2021-06-29T13:36:51Z")

</div>

I created a bug report for this: [[APM] Add minimum bucket size when using metric powered ui · Issue #103661 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/103661). Aiming to get this fixed for 7.14 but I can't promise anything.

---

<div class="post-metadata">

**Author:** ![ebuildy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebuildy/32/6070_2.png) [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Post date:** [July 5, 2021, 8:06am UTC](https://discuss.elastic.co/t/what-is-timestamp-field-exactly/277189/5 "2021-07-05T08:06:24Z")

</div>

thanks you for the insights!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 26, 2021, 4:07am UTC](https://discuss.elastic.co/t/what-is-timestamp-field-exactly/277189/6 "2021-07-26T04:07:21Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
