# Changing timestamp to servertime recieved

**URL:** <https://community.graylog.org/t/changing-timestamp-to-servertime-recieved/3782>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules, time-stamp-issuespl\
**Created:** [January 12, 2018, 8:41am UTC](https://community.graylog.org/t/changing-timestamp-to-servertime-recieved/3782 "2018-01-12T08:41:55Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mr\_Reyes](https://avatars.discourse-cdn.com/v4/letter/m/0ea827/32.png) [@Mr\_Reyes](https://community.graylog.org/u/Mr_Reyes)\
**Post date:** [January 12, 2018, 8:41am UTC](https://community.graylog.org/t/changing-timestamp-to-servertime-recieved/3782/1 "2018-01-12T08:41:55Z")

</div>

is there a easier way to change the timestamp such that it reflects the servertime when the msg was recieved, and not the stamp set by the equipment sending the msg?

can i do it in the pipeline, with a rule?

im having a lot of issues with timezones, some of the equipment stamps the times an hour wrong,

---

<div class="post-metadata">

**Author:** ![Mr\_Reyes](https://avatars.discourse-cdn.com/v4/letter/m/0ea827/32.png) [@Mr\_Reyes](https://community.graylog.org/u/Mr_Reyes)\
**Post date:** [January 12, 2018, 9:03am UTC](https://community.graylog.org/t/changing-timestamp-to-servertime-recieved/3782/2 "2018-01-12T09:03:00Z")

</div>

I have tried with a:

rule “Rotate Timestamp to timestamp” when has\_field(“message”)  
then  
set\_field(“timestamp”, to\_string($message.Timestamp));  
end

Because i have both values in the message allready, the timestamp is the servertime, and the Timestamp is the one from the device.

this doesnt work though…

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [January 12, 2018, 9:16am UTC](https://community.graylog.org/t/changing-timestamp-to-servertime-recieved/3782/3 "2018-01-12T09:16:41Z")

</div>

The “timestamp” field is required to be a proper date/time object.

Try using [`parse_date()`](http://docs.graylog.org/en/2.4/pages/pipelines/functions.html#parse-date) to parse the desired date/time string.

---

<div class="post-metadata">

**Author:** ![Mr\_Reyes](https://avatars.discourse-cdn.com/v4/letter/m/0ea827/32.png) [@Mr\_Reyes](https://community.graylog.org/u/Mr_Reyes)\
**Post date:** [January 12, 2018, 11:36am UTC](https://community.graylog.org/t/changing-timestamp-to-servertime-recieved/3782/4 "2018-01-12T11:36:42Z")

</div>

hmmm tried with:

rule "set timestamp"  
when  
true  
then  
let new\_date = parse\_date(to\_string($message.timestamp),“yyyy-MM-ddTHH:mm:ss.SSSZ”);  
set\_field(“Timestamp”, new\_date);  
end

but then the msg ends in error 😕

---

<div class="post-metadata">

**Author:** ![Mr\_Reyes](https://avatars.discourse-cdn.com/v4/letter/m/0ea827/32.png) [@Mr\_Reyes](https://community.graylog.org/u/Mr_Reyes)\
**Post date:** [January 12, 2018, 11:38am UTC](https://community.graylog.org/t/changing-timestamp-to-servertime-recieved/3782/5 "2018-01-12T11:38:59Z")

</div>

i have got the timestamp syntox as follows:  
2018-01-12T11:37:10.526Z  
and i’ve tried to match with  
yyyy-MM-ddTHH:mm:ss.SSSZ

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [January 12, 2018, 1:17pm UTC](https://community.graylog.org/t/changing-timestamp-to-servertime-recieved/3782/6 "2018-01-12T13:17:51Z")

</div>

“Timestamp” and “timestamp” are different fields. You should make up your mind which of both you want to use.  
Your previous posts are a bit contradictory to each other.

---

<div class="post-metadata">

**Author:** ![Mr\_Reyes](https://avatars.discourse-cdn.com/v4/letter/m/0ea827/32.png) [@Mr\_Reyes](https://community.graylog.org/u/Mr_Reyes)\
**Post date:** [January 15, 2018, 9:17am UTC](https://community.graylog.org/t/changing-timestamp-to-servertime-recieved/3782/7 "2018-01-15T09:17:24Z")

</div>

im sorry if it wasen’t specifik enough.

 ![52](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/1/17bdabddf98b0d473539210b17af55e8f2d0abbb.png)

im trying to set the “timestamp” lower right corner on pic, to the “Timetamp”, Upper left corner

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [January 15, 2018, 9:32am UTC](https://community.graylog.org/t/changing-timestamp-to-servertime-recieved/3782/8 "2018-01-15T09:32:43Z")

</div>

These are already the same (except for the timezone they’re displayed in).

Related GitHub issue:  
[https://github.com/Graylog2/graylog2-server/issues/2689](https://github.com/Graylog2/graylog2-server/issues/2689)

---

<div class="post-metadata">

**Author:** ![Mr\_Reyes](https://avatars.discourse-cdn.com/v4/letter/m/0ea827/32.png) [@Mr\_Reyes](https://community.graylog.org/u/Mr_Reyes)\
**Post date:** [January 17, 2018, 10:29am UTC](https://community.graylog.org/t/changing-timestamp-to-servertime-recieved/3782/9 "2018-01-17T10:29:41Z")

</div>

thnx 🙂  
i found out that libre had just implementet an timezone function against graylog integration, so that it can interpert the timestamps correctly

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [January 31, 2018, 10:29am UTC](https://community.graylog.org/t/changing-timestamp-to-servertime-recieved/3782/10 "2018-01-31T10:29:45Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
