# Change the timestamp format from yyyy-MM-dd HH:mm:ss.SSS Z to yyyy/MM/dd HH:mm:ss.SSS Z with pipeline rule

**URL:** <https://community.graylog.org/t/change-the-timestamp-format-from-yyyy-mm-dd-hhss-sss-z-to-yyyy-mm-dd-hhss-sss-z-with-pipeline-rule/27245>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules\
**Created:** [January 12, 2023, 7:03am UTC](https://community.graylog.org/t/change-the-timestamp-format-from-yyyy-mm-dd-hhss-sss-z-to-yyyy-mm-dd-hhss-sss-z-with-pipeline-rule/27245 "2023-01-12T07:03:06Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![hungv35](https://avatars.discourse-cdn.com/v4/letter/h/e274bd/32.png) [@hungv35](https://community.graylog.org/u/hungv35)\
**Post date:** [January 12, 2023, 7:03am UTC](https://community.graylog.org/t/change-the-timestamp-format-from-yyyy-mm-dd-hhss-sss-z-to-yyyy-mm-dd-hhss-sss-z-with-pipeline-rule/27245/1 "2023-01-12T07:03:07Z")

</div>

i want to change the timestamp format from yyyy-MM-dd HH:mm:ss.SSS Z to yyyy/MM/dd HH:mm:ss.SSS Z with pipeline rule but when i create a rule below it’s seem not work.  
Graylog version 4.1  
Guest OS: Ubuntu 20.  
Time configuration  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/a/a98c07c05a031b6c3bb53b0452c4540696bf455d.png)  
here my pipeline rule:

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/a/a64408d2ca1314c0f6f11edc3f66885316199a8f.png)

here my example message:

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/f/f65f03a9e2128ee3537608a7098031911aac6979.png)  
Thank you.

---

<div class="post-metadata">

**Author:** ![patrickmann](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/patrickmann/32/9091_2.png) [@patrickmann](https://community.graylog.org/u/patrickmann)\
**Post date:** [January 12, 2023, 8:48am UTC](https://community.graylog.org/t/change-the-timestamp-format-from-yyyy-mm-dd-hhss-sss-z-to-yyyy-mm-dd-hhss-sss-z-with-pipeline-rule/27245/2 "2023-01-12T08:48:25Z")

</div>

When modifying the timestamp I like to assign to a temporary field first while testing. Then you don’t get caught out by messages not showing up in the search because e.g. they end up being in a different timezone.

Also check the processing failure stream for error messages.

---

<div class="post-metadata">

**Author:** ![hungv35](https://avatars.discourse-cdn.com/v4/letter/h/e274bd/32.png) [@hungv35](https://community.graylog.org/u/hungv35)\
**Post date:** [January 13, 2023, 3:11am UTC](https://community.graylog.org/t/change-the-timestamp-format-from-yyyy-mm-dd-hhss-sss-z-to-yyyy-mm-dd-hhss-sss-z-with-pipeline-rule/27245/3 "2023-01-13T03:11:45Z")

</div>

thanks for reply, i got this error message

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/4/402d04d12c54136266613c23b701f7e7cc98b44b.png)

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [January 13, 2023, 3:28am UTC](https://community.graylog.org/t/change-the-timestamp-format-from-yyyy-mm-dd-hhss-sss-z-to-yyyy-mm-dd-hhss-sss-z-with-pipeline-rule/27245/4 "2023-01-13T03:28:54Z")

</div>

Hey @hungv35

I have this in my tool kit not sure it it will work for ya.

```auto
rule "replace timestamp"
when
    has_field("timestamp")
then    
    let new_date = parse_date(to_string($message.timestamp), "yyyy-MM-dd'T'HH:mm:ss.SSS","CST"); ///Centeral time Zone
    set_field("timestamp1", new_date);
end

```

---

<div class="post-metadata">

**Author:** ![hungv35](https://avatars.discourse-cdn.com/v4/letter/h/e274bd/32.png) [@hungv35](https://community.graylog.org/u/hungv35)\
**Post date:** [January 13, 2023, 3:47am UTC](https://community.graylog.org/t/change-the-timestamp-format-from-yyyy-mm-dd-hhss-sss-z-to-yyyy-mm-dd-hhss-sss-z-with-pipeline-rule/27245/5 "2023-01-13T03:47:42Z")

</div>

hmmm, i tried as you said, but it still get the same error message. is there any possibility to change the timestamp format as i want

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [January 13, 2023, 4:00am UTC](https://community.graylog.org/t/change-the-timestamp-format-from-yyyy-mm-dd-hhss-sss-z-to-yyyy-mm-dd-hhss-sss-z-with-pipeline-rule/27245/6 "2023-01-13T04:00:44Z")

</div>

hey,  
_timestamp_ field is default by elasticsearch index template.  
Try creating a new field called something like “new\_timestamp” see if that works.

---

<div class="post-metadata">

**Author:** ![hungv35](https://avatars.discourse-cdn.com/v4/letter/h/e274bd/32.png) [@hungv35](https://community.graylog.org/u/hungv35)\
**Post date:** [January 13, 2023, 4:08am UTC](https://community.graylog.org/t/change-the-timestamp-format-from-yyyy-mm-dd-hhss-sss-z-to-yyyy-mm-dd-hhss-sss-z-with-pipeline-rule/27245/7 "2023-01-13T04:08:25Z")

</div>

yes, i tried, but message error is still, and the new field not show.

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [January 13, 2023, 4:10am UTC](https://community.graylog.org/t/change-the-timestamp-format-from-yyyy-mm-dd-hhss-sss-z-to-yyyy-mm-dd-hhss-sss-z-with-pipeline-rule/27245/8 "2023-01-13T04:10:08Z")

</div>

can you show the updated version of your pipeline?  
EDIT Im going to test it out in my lab.

---

<div class="post-metadata">

**Author:** ![hungv35](https://avatars.discourse-cdn.com/v4/letter/h/e274bd/32.png) [@hungv35](https://community.graylog.org/u/hungv35)\
**Post date:** [January 13, 2023, 4:16am UTC](https://community.graylog.org/t/change-the-timestamp-format-from-yyyy-mm-dd-hhss-sss-z-to-yyyy-mm-dd-hhss-sss-z-with-pipeline-rule/27245/9 "2023-01-13T04:16:37Z")

</div>

yeah sure, but i think the new format timestamp is incorrect, my idea is when i have a message with timestamp like 2023-01-13 11:10:48.000 +07:00 and the pipeline will change it to (dd/MM/yyyy hh:mm:ss.S timezone. example: 13/01/2023 11:10:48 +07:00)

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/1/1da3afbd5e7721e38d01f51d2233c407c7527a8d.png)

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [January 13, 2023, 5:11am UTC](https://community.graylog.org/t/change-the-timestamp-format-from-yyyy-mm-dd-hhss-sss-z-to-yyyy-mm-dd-hhss-sss-z-with-pipeline-rule/27245/10 "2023-01-13T05:11:13Z")

</div>

Hey,  
After testing a few of these pipeline I cant seam to get your format.

Correct me is im wrong but you have this

```auto
yyyy-MM-dd HH:mm:ss.SSS Z

```

and you want this

```auto
yyyy/MM/dd HH:mm:ss.SSS Z

```

I tries a few of my pipes , and it still didnt work.  
Example of one I know that works but ended up with same error.

```auto
rule "add ingestion timestamp"
when
 true
then
 let ingestion_time = now();
 let timestamp_time = parse_date(to_string($message.timestamp), "yyyy/MM/dd'T'HH:mm:ss.SSSZ");
 set_field("timestamp_text", to_string($message.timestamp,"default_text"));
 set_field("timestamp2b", $message.timestamp);
 set_field("timestamp2", timestamp_time);
 set_field("ingestion_time",ingestion_time);
 set_field("ingestion_time_millis", ingestion_time.millis); set_field("timestamp_millis",to_date($message.timestamp).millis);
end

```

I think Elasticsearch doesnt like these ` "/"` perhaps @tmacgbay would know better.

---

<div class="post-metadata">

**Author:** ![hungv35](https://avatars.discourse-cdn.com/v4/letter/h/e274bd/32.png) [@hungv35](https://community.graylog.org/u/hungv35)\
**Post date:** [January 13, 2023, 5:32am UTC](https://community.graylog.org/t/change-the-timestamp-format-from-yyyy-mm-dd-hhss-sss-z-to-yyyy-mm-dd-hhss-sss-z-with-pipeline-rule/27245/11 "2023-01-13T05:32:02Z")

</div>

yeah, thank you for your support.  
i just curl -X GET ‘[http://localhost:9200/graylog\_deflector/\_mapping?pretty](http://localhost:9200/graylog_deflector/_mapping?pretty)’  
and got this one, is there any way to change format timestamp on elasticsearch  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/9/97a41297ed8719b7e6cd94d05d847d22e50ec2ed.png)

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [January 13, 2023, 5:35am UTC](https://community.graylog.org/t/change-the-timestamp-format-from-yyyy-mm-dd-hhss-sss-z-to-yyyy-mm-dd-hhss-sss-z-with-pipeline-rule/27245/12 "2023-01-13T05:35:37Z")

</div>

Hey,

I really dont know. I would take a guess probably , first I would see if elasticearch would be able to to that. Perhaps create a new index template for a new index set. This way is something goes horribly wrong your not going to mess up all your indices.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [January 27, 2023, 5:35am UTC](https://community.graylog.org/t/change-the-timestamp-format-from-yyyy-mm-dd-hhss-sss-z-to-yyyy-mm-dd-hhss-sss-z-with-pipeline-rule/27245/13 "2023-01-27T05:35:48Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
