# Add date field from IIS-log

**URL:** <https://discuss.elastic.co/t/add-date-field-from-iis-log/88596>\
**Category:** Logstash\
**Created:** [June 7, 2017, 2:30pm UTC](https://discuss.elastic.co/t/add-date-field-from-iis-log/88596 "2017-06-07T14:30:32Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Robert\_Andersson](https://avatars.discourse-cdn.com/v4/letter/r/e8c25b/32.png) [@Robert\_Andersson](https://discuss.elastic.co/u/Robert_Andersson)\
**Post date:** [June 7, 2017, 2:30pm UTC](https://discuss.elastic.co/t/add-date-field-from-iis-log/88596/1 "2017-06-07T14:30:32Z")

</div>

Hi, i'm currently trying to add an additional date field for when the log was created called log\_timestamp. But the Date filter does not seem to convert log\_timestamp into a date type.  
My config is below.

```
  filter {
      if [type] == 'iis_log' {
        if [message] =~ "^#" {
          drop {}
        }
        grok {
          match => { "message" => "%{TIMESTAMP_ISO8601:log_timestamp} %{IPORHOST:hostip} %{WORD:method} %{URIPATH:page} %{NOTSPACE:query} %{NUMBER:port:int} %{NOTSPACE:username} %{IPORHOST:clientip} %{NOTSPACE:useragent} %{NOTSPACE:cs-host} %{NUMBER:status:int} %{NUMBER:response:int} %{NUMBER:win32status:int} %{NUMBER:timetaken:int}" }
        }
        geoip {
          source => "clientip"
          target => "geoip"
        }
        date {
          match => ["log_timestamp", "YYYY-MM-dd HH:mm:ss"]
          target => "log_timestamp"
        }
      }
    }
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 9, 2017, 9:34am UTC](https://discuss.elastic.co/t/add-date-field-from-iis-log/88596/2 "2017-06-09T09:34:02Z")

</div>

Please give an example of a `log_timestamp` value that isn't converted as you expect.

---

<div class="post-metadata">

**Author:** ![Robert\_Andersson](https://avatars.discourse-cdn.com/v4/letter/r/e8c25b/32.png) [@Robert\_Andersson](https://discuss.elastic.co/u/Robert_Andersson)\
**Post date:** [June 9, 2017, 5:59pm UTC](https://discuss.elastic.co/t/add-date-field-from-iis-log/88596/3 "2017-06-09T17:59:17Z")

</div>

Thank you for answering.  
It looks like this  
`2017-04-03 23:57:46`

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 12, 2017, 5:55am UTC](https://discuss.elastic.co/t/add-date-field-from-iis-log/88596/4 "2017-06-12T05:55:04Z")

</div>

That should be fine. So is the date filter failing (resulting in a `_dateparsefailure` tag in your events) or is the problem that the resulting field in ES isn't a date field? In the latter case the problem is probably that the field at some point was mapped as a string and that won't change just because what you're currently sending in that field looks like a timestamp. One of way fixing the problem is deleting the index and starting over (since you might not have useful data there anyway), optionally with an index template that explicitly maps the `log_timestamp` field as a date field.

Any particular reason you want to call the timestamp field `log_timestamp` field instead of the default `@timestamp`? The latter will already have the correct mapping if you use Logstash's default index template.

---

<div class="post-metadata">

**Author:** ![Robert\_Andersson](https://avatars.discourse-cdn.com/v4/letter/r/e8c25b/32.png) [@Robert\_Andersson](https://discuss.elastic.co/u/Robert_Andersson)\
**Post date:** [June 12, 2017, 9:16am UTC](https://discuss.elastic.co/t/add-date-field-from-iis-log/88596/5 "2017-06-12T09:16:37Z")

</div>

Thanks for the answer it helped us solving it by doing the following.

Delete the old index.  
Add the following field under the `properties` field to our filebeat template.

```
"log_timestamp": {
  "type": "date"
 }

```

We use `@timestamp` as well but want an additional `date` for the log.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2017, 9:16am UTC](https://discuss.elastic.co/t/add-date-field-from-iis-log/88596/6 "2017-07-10T09:16:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
