# Winlogbeat does not have a proper timestamp field

**URL:** <https://discuss.elastic.co/t/winlogbeat-does-not-have-a-proper-timestamp-field/60513>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [September 14, 2016, 2:36pm UTC](https://discuss.elastic.co/t/winlogbeat-does-not-have-a-proper-timestamp-field/60513 "2016-09-14T14:36:37Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![pramod\_kumar](https://avatars.discourse-cdn.com/v4/letter/p/97f17d/32.png) [@pramod\_kumar](https://discuss.elastic.co/u/pramod_kumar)\
**Post date:** [September 14, 2016, 2:36pm UTC](https://discuss.elastic.co/t/winlogbeat-does-not-have-a-proper-timestamp-field/60513/1 "2016-09-14T14:36:37Z")

</div>

Winlogbeat doesnot have a Proper timestamp filed,  
Please help me with this issue.

thanks  
pramod

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [September 14, 2016, 2:42pm UTC](https://discuss.elastic.co/t/winlogbeat-does-not-have-a-proper-timestamp-field/60513/2 "2016-09-14T14:42:48Z")

</div>

All Winlogbeat events have a [`@timestamp`](https://www.elastic.co/guide/en/beats/winlogbeat/current/exported-fields-common.html#_timestamp) field that contains the time that the Windows event log record was originally created.

> <https://github.com/elastic/beats/blob/master/winlogbeat/eventlog/eventlog.go#L60>

---

<div class="post-metadata">

**Author:** ![pramod\_kumar](https://avatars.discourse-cdn.com/v4/letter/p/97f17d/32.png) [@pramod\_kumar](https://discuss.elastic.co/u/pramod_kumar)\
**Post date:** [September 15, 2016, 11:59am UTC](https://discuss.elastic.co/t/winlogbeat-does-not-have-a-proper-timestamp-field/60513/3 "2016-09-15T11:59:01Z")

</div>

Yes, it has the @timestamp fileld. But this timestamp filed has the time when the event has been parsed by logstash rather than the time when it has been logged(created) as windows event.

Can you please help me to resolve this issue ??

Thanks  
Pramod

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [September 15, 2016, 12:15pm UTC](https://discuss.elastic.co/t/winlogbeat-does-not-have-a-proper-timestamp-field/60513/4 "2016-09-15T12:15:22Z")

</div>

Please share the Logstash configuration and version you are using.

---

<div class="post-metadata">

**Author:** ![pramod\_kumar](https://avatars.discourse-cdn.com/v4/letter/p/97f17d/32.png) [@pramod\_kumar](https://discuss.elastic.co/u/pramod_kumar)\
**Post date:** [September 15, 2016, 1:06pm UTC](https://discuss.elastic.co/t/winlogbeat-does-not-have-a-proper-timestamp-field/60513/5 "2016-09-15T13:06:46Z")

</div>

Hi andrewroh,

Winlogbeat version: 1.2.3, Logstash version: 2.3.3, Elasticsearch:  
2.3.3 and Kibana: 4.5.1.

```auto
# The # character at the beginning of a line indicates a comment. Use
# comments to describe your configuration.
input {
    beats {
        port => 5044
    }
}

# The filter part of this file is commented out to indicate that it is
# optional.
filter {
mutate {
gsub => [
"meassage", "\r\n", " ",
"message", "\n", " ",
"message", "\t", " "
]
}

if [message] =~ /PFError/ {
grok {
match => ["message","%{GREEDYDATA} <ErrorCode>%{DATA:HRESULT}</ErrorCode> <Trial>%{DATA:Trial}</Trial> <Details>%{DATA:Detail}</Details> %{GREEDYDATA}"]
}
}
if [message] =~ /HRESULT/ { 
grok {
match => ["message","%{GREEDYDATA} HRESULT=%{DATA:HRESULT}; Trial=%{DATA:Trial}; Details=%{DATA:Detail}[.;] %{GREEDYDATA}" ]
}
}
if [message] =~ /WINNT/ {
grok {
match => ["message","%{GREEDYDATA} Exception code: %{DATA:HRESULT} %{GREEDYDATA}"]
}
mutate{
          add_field=>{
            "Detail"=>"Unhandled access exception"
            "Trial"=>" "
          }
}
}
if [message] =~ /Error| Critical/ {
  mutate {
  add_tag => ["Error_tag"]  
}
}

if "MiddleTier" in [tags]{
        mutate {
          add_field => {
              "gbu_name" => "%{tags[0]}"
              "prod_name" => "%{tags[1]}"
              "version" => "%{tags[2]}"
              "env_type" => "%{tags[3]}"
              "tier" => "%{tags[4]}"
              "tenantName" => "%{tags[5]}"
              }
          lowercase => ["gbu_name"]
          lowercase => ["prod_name"]
          lowercase => ["env_type"]
          lowercase => ["tier"]
          lowercase => ["tenantName"]
          join => { "gbu_name" => "" }
          join => { "prod_name" => "" }
          join => { "version" => "" }
          join => { "env_type" => "" }
          join => { "tier" => "" }
          join => { "tenantName" => "" }
          }
      }
 
}

output{
 stdout{ 
      codec => dots
    }
  if "_grokparsefailure" not in [tags]{
    if "MiddleTier" in [tags]{
      elasticsearch{
      hosts=>["localhost:9200"]
        index=> "wl-logdetails"        
      }
      if "Error_tag" in [tags]{
      elasticsearch{
      hosts=>["localhost:9200"]
        index=> "wl-logsummary"        
        }
      }
     }
    }
  }

```

Thanks  
Pramod

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [September 15, 2016, 2:03pm UTC](https://discuss.elastic.co/t/winlogbeat-does-not-have-a-proper-timestamp-field/60513/6 "2016-09-15T14:03:17Z")

</div>

I don't see anything obvious in your Logstash configuration that would be modifying the `@timestamp` field coming from Beats. I suggest that you do a test without any filters and see what the `@timestamp` is. It should definitely be the time that the event log record was originally created.

```auto
input {
  beats {
    port => 5044
  }
}

output {
  stdout { codec => rubydebug { metadata => true } } 
}

```

Then after doing this test, start adding back in filters one-by-one to see where the `@timestamp` mutation is occurring.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 6, 2016, 2:03pm UTC](https://discuss.elastic.co/t/winlogbeat-does-not-have-a-proper-timestamp-field/60513/7 "2016-10-06T14:03:54Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
