# Adding 1 day to the date

**URL:** <https://discuss.elastic.co/t/adding-1-day-to-the-date/129168>\
**Category:** Logstash\
**Created:** [April 23, 2018, 7:24pm UTC](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168 "2018-04-23T19:24:53Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![HRG](https://avatars.discourse-cdn.com/v4/letter/h/a4c791/32.png) [@HRG](https://discuss.elastic.co/u/HRG)\
**Post date:** [April 23, 2018, 7:24pm UTC](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168/1 "2018-04-23T19:24:53Z")

</div>

I am new to Logstash and have a requirement to add 1 day to the date(Businessdate) and compare log event date with Businessdate. Can you please suggest how to achieve this.

Ex: Parsed string to extract YEAR, MONTH AND day  
grok {  
match =\> ["BusinessDate", "%{YEAR:year}%{MONTHNUM:month}%{MONTHDAY:day}"]  
}  
#Setting time to 3am  
mutate {  
add\_field =\> {  
ExpectedTime =\> "03:00:00:000"  
}  
}

#Making date time  
mutate {  
add\_field =\> {  
BusinesDateTime =\> "%{year}-%{month}-%{day} %{ExpectedTime}"  
}  
}

#Convert/match to Datetime  
date  
{  
match =\> ["BusinesDateTime", "YYYY-MM-DD HH:mm:ss.SSS"]   
}

Now i would like to add 1 day to the "BusinessDateTime".

When i read some of existing posts, it says use "ruby" plug-in. Please let me know how to use ruby functions to add 1 day.

Can you please help how to achive this?

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [April 24, 2018, 7:30am UTC](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168/2 "2018-04-24T07:30:05Z")

</div>

This works:

```
ruby {
    code => 'event.set("@timestamp", LogStash::Timestamp.new(event.get("@timestamp")+86400))'
  }
```

---

<div class="post-metadata">

**Author:** ![HRG](https://avatars.discourse-cdn.com/v4/letter/h/a4c791/32.png) [@HRG](https://discuss.elastic.co/u/HRG)\
**Post date:** [April 24, 2018, 1:49pm UTC](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168/3 "2018-04-24T13:49:19Z")

</div>

Thank you Jenni for the info. I have tried but getting below error. Can you please advise anything is missing in the code

**Error**  
[2018-04-24T09:43:48,356][ERROR][logstash.filters.ruby] Ruby exception occurred: no implicit conversion of Fixnum into String  
[2018-04-24T09:43:48,356][ERROR][logstash.filters.ruby] Ruby exception occurred: no implicit conversion of Fixnum into String  
[2018-04-24T09:43:48,357][ERROR][logstash.filters.ruby] Ruby exception occurred: no implicit conversion of Fixnum into String

**Code**  
grok {  
match =\> ["BusinessDate", "%{YEAR:year}%{MONTHNUM:month}%{MONTHDAY:day}"]  
overwrite =\> ["message"]  
}

```
    if "_grokparsefailure" in [tags] {		
		mutate {				
			remove_tag => ["_grokparsefailure"]					
		}				
	}

# Set Timestamp

mutate {
	add_field => {
		ExpectedTime => "03:00:00:000"
	}
}

mutate {
	add_field => {
		BusinesDateTime => "%{year}-%{month}-%{day} %{ExpectedTime}"
	}
}
#Not required ExptectedTime in output
mutate {
	remove_field => [ExpectedTime]
}

#Convert to Date
date
{
	match => ["BusinesDateTime", "YYYY-MM-DD HH:mm:ss.SSS"]				
}

#Adding one day to BusinessDateTime

ruby {
code => 'event.set("BusinesDateTime", LogStash::Timestamp.new(event.get("BusinesDateTime")+86400))'
}
```

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [April 24, 2018, 1:55pm UTC](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168/4 "2018-04-24T13:55:04Z")

</div>

The default target of date{} is @timestamp. So your BusinesDateTime is not a LogStash::Timestamp at this point, but a string. If you want to convert BusinesDateTime to a timestamp, you have to specify this field as the target. That's probably causing the error.

---

<div class="post-metadata">

**Author:** ![HRG](https://avatars.discourse-cdn.com/v4/letter/h/a4c791/32.png) [@HRG](https://discuss.elastic.co/u/HRG)\
**Post date:** [April 24, 2018, 2:06pm UTC](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168/5 "2018-04-24T14:06:17Z")

</div>

#Convert to Date  
date  
{  
match =\> ["BusinesDateTime", "YYYY-MM-DD HH:mm:ss.SSS"]   
target =\> "BusinesDateTime"  
}

```
#Adding one day to BusinessDateTime

ruby {
code => 'event.set("BusinesDateTime", LogStash::Timestamp.new(event.get("BusinesDateTime")+86400))'
}

```

[2018-04-24T09:59:53,432][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refre  
sh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>fa  
lse}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}],  
"properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "lati  
tude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
[2018-04-24T09:59:53,460][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//127.0.0.1:9200](https://127.0.0.1:9200)"]}  
[2018-04-24T09:59:54,268][INFO][logstash.pipeline] Pipeline started succesfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x67cdab run\>"}  
[2018-04-24T09:59:54,318][INFO][logstash.agent] Pipelines running {:count=\>1, :pipelines=\>["main"]}  
[2018-04-24T09:59:55,409][ERROR][logstash.filters.ruby] Ruby exception occurred: no implicit conversion of Fixnum into String  
[2018-04-24T09:59:55,426][ERROR][logstash.filters.ruby] Ruby exception occurred: no implicit conversion of Fixnum into String  
[2018-04-24T09:59:55,428][ERROR][logstash.filters.ruby] Ruby exception occurred: no implicit conversion of Fixnum into String

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [April 24, 2018, 2:29pm UTC](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168/6 "2018-04-24T14:29:26Z")

</div>

Hm. Strange. Two questions:

1. What does the ruby debug output look like without the ruby filter? Maybe that can give us a hint.

2. Does this work?

---

<div class="post-metadata">

**Author:** ![HRG](https://avatars.discourse-cdn.com/v4/letter/h/a4c791/32.png) [@HRG](https://discuss.elastic.co/u/HRG)\
**Post date:** [April 24, 2018, 2:36pm UTC](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168/7 "2018-04-24T14:36:13Z")

</div>

Thank you. With this new conversion, its not giving any error but not converting date correctly.

BusinessDate BusinesDateTime(input) BusinesDateTimeConverted (After adding one day)  
20180419 2018-04-19 03:00:00:000 1970-01-02T00:33:38.000Z

Am i missing anything please?. Its showing as 1970 year instead of April 20th.

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [April 24, 2018, 2:40pm UTC](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168/8 "2018-04-24T14:40:04Z")

</div>

There's probably something wrong with the BusinesDateTime value before the ruby filter, so the UNIX timestamp that the new Timestamp object is based on, is 0+86400 = 1970-01-01 plus one day.

... Your ExpectedTime ends with ':000', but your pattern ends with '.SSS'.

---

<div class="post-metadata">

**Author:** ![HRG](https://avatars.discourse-cdn.com/v4/letter/h/a4c791/32.png) [@HRG](https://discuss.elastic.co/u/HRG)\
**Post date:** [April 24, 2018, 3:02pm UTC](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168/9 "2018-04-24T15:02:45Z")

</div>

Means..i should not end with "SSS". Please let me know what i should end with the milliseconds part.

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [April 24, 2018, 3:15pm UTC](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168/10 "2018-04-24T15:15:09Z")

</div>

There's a colon in your data, not a period.

---

<div class="post-metadata">

**Author:** ![HRG](https://avatars.discourse-cdn.com/v4/letter/h/a4c791/32.png) [@HRG](https://discuss.elastic.co/u/HRG)\
**Post date:** [April 24, 2018, 4:00pm UTC](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168/11 "2018-04-24T16:00:10Z")

</div>

Thank you for spotting the issue Jenni. Your solution is working . Thank you.

BusinesDateTime BusinesDateTimeConverted LogEventTimeStamp  
2018-01-19T08:00:00.000Z 2018-01-20T08:00:00.000Z April 19th 2018, 13:15:09.000

From the above the BusinessDateTime is : 2018-01-19 03:00:00.000

Can you please advise what to do to get to YYYY-MM-DD HH:MI:SS.SSS format. The reason is i need to compare both `logEventTimeStamp`and `BusinessDateTimeConverted`

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [April 24, 2018, 4:20pm UTC](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168/12 "2018-04-24T16:20:00Z")

</div>

I'm afraid I don't really understand the question. Do you want to convert logEventTimeStamp to a Time object?

---

<div class="post-metadata">

**Author:** ![HRG](https://avatars.discourse-cdn.com/v4/letter/h/a4c791/32.png) [@HRG](https://discuss.elastic.co/u/HRG)\
**Post date:** [April 24, 2018, 8:30pm UTC](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168/13 "2018-04-24T20:30:25Z")

</div>

I would like to see both "BusinessDateTimeConverted" and "LogEventTImeStamp" to "YYYY-MM-DD HH:MI;SS.SSS" format.Currently it is showing as "2018-01-19T08:00:00.000Z" format.

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [April 24, 2018, 8:51pm UTC](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168/14 "2018-04-24T20:51:39Z")

</div>

Business Datetime Converted doesn't really have a fixed format as it is not a string, but a Timestamp object. 2018-01-19T08:00:00.000Z is Logstash's way of displaying it. You could build a formatted string from that Timestamp again. But wouldn't Timestamp objects be more useful for comparisons?

---

<div class="post-metadata">

**Author:** ![HRG](https://avatars.discourse-cdn.com/v4/letter/h/a4c791/32.png) [@HRG](https://discuss.elastic.co/u/HRG)\
**Post date:** [April 25, 2018, 1:49pm UTC](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168/15 "2018-04-25T13:49:21Z")

</div>

Understood. Thank you.

Is this the way we compare dates to add new filed? . Somehow its throwing error.

date {  
if "LogEventTimeStamp" \>= "BusinesDateTimeConverted" {  
mutate {  
add\_field =\> {  
LateFileStatus =\> "LateArrival"  
}   
}   
} else {  
mutate {  
add\_field =\> {  
LateFileStatus =\> "On-Time"  
}   
}   
}   
}

**Error**

[2018-04-25T09:46:11,762][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_i  
or", :message=\>"Expected one of #, =\> at line 114, column 8 (byte 2728) after filter {\n\t\t\n\t#Match patterns based on source log origin

Line 114 is above "if" condition.

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [April 25, 2018, 2:25pm UTC](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168/16 "2018-04-25T14:25:06Z")

</div>

Could you post more of your configuration? The text snippet in those syntax error logs usually ends right before the error. So I'm not sure if the wrong part is even included in the code you posted.

"LogEventTimeStamp" and "BusinesDateTimeConverted" are strings. You want to compare the field values [LogEventTimeStamp] and [BusinesDateTimeConverted] (if these are both timestamps)

---

<div class="post-metadata">

**Author:** ![HRG](https://avatars.discourse-cdn.com/v4/letter/h/a4c791/32.png) [@HRG](https://discuss.elastic.co/u/HRG)\
**Post date:** [April 25, 2018, 2:27pm UTC](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168/17 "2018-04-25T14:27:23Z")

</div>

Please see below

#Extract Business date from file

```
grok {
	match => ["file", "%{WORD}.%{WORD:BusinessDate}.%{GREEDYDATA:FileLastPart}"]		
}      

if "_grokparsefailure" in [tags] {		
	mutate {				
			remove_tag => ["_grokparsefailure"]		
	}				
}

#Parse Business date
	
grok {
	match => ["BusinessDate", "%{YEAR:year}%{MONTHNUM:month}%{MONTHDAY:day}"]
}      

if "_grokparsefailure" in [tags] {		
	mutate {				
			remove_tag => ["_grokparsefailure"]					
	}				
}

# Set Timestamp

mutate {
	add_field => {
		ExpectedTime => "03:00:00.000"
	}
}

mutate {
	add_field => {
		BusinesDateTime => "%{year}-%{month}-%{day} %{ExpectedTime}"
	}
}
#Not required ExptectedTime in output
mutate {
	remove_field => [ExpectedTime]
}

#Convert to Date
date
{
	match => ["BusinesDateTime", "YYYY-MM-DD HH:mm:ss.SSS"]		
	target => "BusinesDateTime"
}

#Adding one day to BusinessDateTime

ruby {
	code => 'event.set("BusinesDateTimeConverted", LogStash::Timestamp.new(Time.at(event.get("BusinesDateTime").to_f+86400)))'				
}
	
#Remove Milliseconds	
mutate {
	gsub => ["LogEventTimeStamp", "\.\d{3}$", ""]
}

#Setting up Log timestamp to LogEventTimeStamp for the given formats.
date
{
	match => ["BusinesDateTimeConverted", "yyyy-MM-dd HH:mm:ss", "MMM dd, yyyy HH:mm:ss", "yyyy-MM-dd HH:mm:ss,SSS", "yyyy-MM-dd HH:mm:ss.SSS"]		
	target => "BusinesDateTimeConverted"		
}

#Setting up Log timestamp to LogEventTimeStamp for the given formats.
date
{
	match => ["LogEventTimeStamp", "yyyy-MM-dd HH:mm:ss", "MMM dd, yyyy HH:mm:ss", "yyyy-MM-dd HH:mm:ss,SSS", "yyyy-MM-dd HH:mm:ss.SSS"]		
	target => "LogEventTimeStamp"		
}

```

#Date comparision  
date  
{  
if "LogEventTimeStamp \>= "BusinesDateTimeConverted" {  
mutate {  
add\_field =\> {  
"LateFileStatus" =\> "LateArrival"  
}   
}   
} else {  
mutate {  
add\_field =\> {  
"LateFileStatus" =\> "On-Time"  
}   
}   
}   
}  
#End of Date Comparision

---

<div class="post-metadata">

**Author:** ![HRG](https://avatars.discourse-cdn.com/v4/letter/h/a4c791/32.png) [@HRG](https://discuss.elastic.co/u/HRG)\
**Post date:** [April 25, 2018, 2:28pm UTC](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168/18 "2018-04-25T14:28:01Z")

</div>

yeah, i wanted to compare both timestamps.

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [April 25, 2018, 2:39pm UTC](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168/19 "2018-04-25T14:39:03Z")

</div>

Where is the line that says "#Match patterns based ...."? The error has to be after that.

Try `if [LogEventTimeStamp] >= [BusinesDateTimeConverted] {` for the comparison.

---

<div class="post-metadata">

**Author:** ![HRG](https://avatars.discourse-cdn.com/v4/letter/h/a4c791/32.png) [@HRG](https://discuss.elastic.co/u/HRG)\
**Post date:** [April 25, 2018, 2:40pm UTC](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168/20 "2018-04-25T14:40:08Z")

</div>

#Extract Business date from file

```
grok {
	match => ["file", "%{WORD}.%{WORD:BusinessDate}.%{GREEDYDATA:FileLastPart}"]		
}      

if "_grokparsefailure" in [tags] {		
	mutate {				
			remove_tag => ["_grokparsefailure"]		
	}				
}

#Parse Business date
	
grok {
	match => ["BusinessDate", "%{YEAR:year}%{MONTHNUM:month}%{MONTHDAY:day}"]
}      

if "_grokparsefailure" in [tags] {		
	mutate {				
			remove_tag => ["_grokparsefailure"]					
	}				
}

# Set Timestamp

mutate {
	add_field => {
		ExpectedTime => "03:00:00.000"
	}
}

mutate {
	add_field => {
		BusinesDateTime => "%{year}-%{month}-%{day} %{ExpectedTime}"
	}
}
#Not required ExptectedTime in output
mutate {
	remove_field => [ExpectedTime]
}

#Convert to Date
date
{
	match => ["BusinesDateTime", "YYYY-MM-DD HH:mm:ss.SSS"]		
	target => "BusinesDateTime"
}

#Adding one day to BusinessDateTime

ruby {
	code => 'event.set("BusinesDateTimeConverted", LogStash::Timestamp.new(Time.at(event.get("BusinesDateTime").to_f+86400)))'				
}
	
#Remove Milliseconds	
mutate {
	gsub => ["LogEventTimeStamp", "\.\d{3}$", ""]
}

#Setting up Log timestamp to LogEventTimeStamp for the given formats.
date
{
	match => ["BusinesDateTimeConverted", "yyyy-MM-dd HH:mm:ss", "MMM dd, yyyy HH:mm:ss", "yyyy-MM-dd HH:mm:ss,SSS", "yyyy-MM-dd HH:mm:ss.SSS"]		
	target => "BusinesDateTimeConverted"		
}

#Setting up Log timestamp to LogEventTimeStamp for the given formats.
date
{
	match => ["LogEventTimeStamp", "yyyy-MM-dd HH:mm:ss", "MMM dd, yyyy HH:mm:ss", "yyyy-MM-dd HH:mm:ss,SSS", "yyyy-MM-dd HH:mm:ss.SSS"]		
	target => "LogEventTimeStamp"		
}

```

#Date comparision  
date  
{  
if "LogEventTimeStamp \>= "BusinesDateTimeConverted" {  
mutate {  
add\_field =\> {  
"LateFileStatus" =\> "LateArrival"  
}   
}   
} else {  
mutate {  
add\_field =\> {  
"LateFileStatus" =\> "On-Time"  
}   
}   
}   
}  
#End of Date Comparision

[Next page](https://discuss.elastic.co/t/adding-1-day-to-the-date/129168.md?page=2)
