# After upgrade to 8.15.2 - csv export not working

**URL:** <https://discuss.elastic.co/t/after-upgrade-to-8-15-2-csv-export-not-working/368902>\
**Category:** Kibana\
**Created:** [October 16, 2024, 11:45am UTC](https://discuss.elastic.co/t/after-upgrade-to-8-15-2-csv-export-not-working/368902 "2024-10-16T11:45:28Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![miiroslavkardos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miiroslavkardos/32/123639_2.png) [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Post date:** [October 16, 2024, 11:45am UTC](https://discuss.elastic.co/t/after-upgrade-to-8-15-2-csv-export-not-working/368902/1 "2024-10-16T11:45:28Z")

</div>

Hello All,

I have saved search which i am trying to export to csv.  
But i got error:

```auto
document_parsing_exception Caused by: illegal_argument_exception: Expected text at 1:623 but found START_OBJECT Root causes: document_parsing_exception: [1:726] failed to parse field [payload.searchSource.filter.query.range.@timestamp] of type [date] in document with id '02f59028-923f-4d17-840e-1a63a7dbf1df'. Preview of field's value: '{format=strict_date_optional_time, gte=2024-06-30T22:00:00.000Z, lte=2024-07-31T23:00:00.000Z}'

```

![image](https://us1.discourse-cdn.com/elastic/original/3X/3/2/3256cfc2a8c673dc8d69609b4c7f3167dcf4df00.png)

My @timestamp field is in type date.

And data are from datastream.

Also added format to timestamp field :  
dd.MM.yyyy HH:mm:ss

What is the issue?

---

<div class="post-metadata">

**Author:** ![miiroslavkardos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miiroslavkardos/32/123639_2.png) [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Post date:** [October 17, 2024, 12:21pm UTC](https://discuss.elastic.co/t/after-upgrade-to-8-15-2-csv-export-not-working/368902/2 "2024-10-17T12:21:12Z")

</div>

These are my mappings :  
Tried everyone none is working.

```auto
".ds-winlogbeat-8.13.1-2024.10.17-000049": {
    "mappings": {
      "@timestamp": {
        "full_name": "@timestamp",
        "mapping": {
          "@timestamp": {
            "type": "date",
            "format": "strict_date_optional_time||epoch_millis||strict_date"
          }
        }
      }
    }
  },
  ".ds-winlogbeat-8.13.1-2024.10.08-000042": {
    "mappings": {
      "@timestamp": {
        "full_name": "@timestamp",
        "mapping": {
          "@timestamp": {
            "type": "date"
          }
        }
      }
    }
  },
  ".ds-winlogbeat-8.13.1-2024.10.16-000043": {
    "mappings": {
      "@timestamp": {
        "full_name": "@timestamp",
        "mapping": {
          "@timestamp": {
            "type": "date",
            "format": "strict_date_optional_time||epoch_millis||dd.MM.yyyy HH:mm:ss"
          }
        }
      }
    }
  },

```

---

<div class="post-metadata">

**Author:** ![miiroslavkardos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miiroslavkardos/32/123639_2.png) [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Post date:** [October 22, 2024, 7:27am UTC](https://discuss.elastic.co/t/after-upgrade-to-8-15-2-csv-export-not-working/368902/3 "2024-10-22T07:27:20Z")

</div>

Any hints what can cause issue?

---

<div class="post-metadata">

**Author:** ![miiroslavkardos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miiroslavkardos/32/123639_2.png) [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Post date:** [October 29, 2024, 12:22pm UTC](https://discuss.elastic.co/t/after-upgrade-to-8-15-2-csv-export-not-working/368902/4 "2024-10-29T12:22:50Z")

</div>

I still cannot export data, is there someone who could help me with this? Someone from supprot team?

---

<div class="post-metadata">

**Author:** ![miiroslavkardos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miiroslavkardos/32/123639_2.png) [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Post date:** [November 8, 2024, 1:48pm UTC](https://discuss.elastic.co/t/after-upgrade-to-8-15-2-csv-export-not-working/368902/5 "2024-11-08T13:48:14Z")

</div>

this is the range i am using :

```auto
 "query": {
    "bool": {
      "must": [
        {
          "query_string": {
            "query": "user.domain: (hq OR HQ OR HQ.COM) ",
            "analyze_wildcard": true,
            "time_zone": "Europe/Bratislava"
          }
        }
      ],
      "filter": [
        {
          "range": {
            "@timestamp": {
              "format": "strict_date_optional_time",
              "gte": "2024-07-31T22:00:00.000Z",
              "lte": "2024-10-31T23:00:00.000Z"
            }

```

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [November 11, 2024, 6:33pm UTC](https://discuss.elastic.co/t/after-upgrade-to-8-15-2-csv-export-not-working/368902/6 "2024-11-11T18:33:11Z")

</div>

Could you please confirm if you still have issues or it is fixed?

---

<div class="post-metadata">

**Author:** ![miiroslavkardos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miiroslavkardos/32/123639_2.png) [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Post date:** [November 12, 2024, 8:52am UTC](https://discuss.elastic.co/t/after-upgrade-to-8-15-2-csv-export-not-working/368902/7 "2024-11-12T08:52:39Z")

</div>

Hello @Tortoise,  
Thanks for reaching out, i am still experiencing the issue it is happening in every index in every export not only winlogbeat.

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [November 24, 2024, 4:05am UTC](https://discuss.elastic.co/t/after-upgrade-to-8-15-2-csv-export-not-working/368902/8 "2024-11-24T04:05:42Z")

</div>

Sorry for the delay :

Could you please try the query format :

"range": {  
"@timestamp": {  
"gte": "2024-07-31T22:00:00.000Z",  
"lte": "2024-10-31T23:00:00.000Z"  
}  
}

---

<div class="post-metadata">

**Author:** ![miiroslavkardos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miiroslavkardos/32/123639_2.png) [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Post date:** [November 26, 2024, 10:42am UTC](https://discuss.elastic.co/t/after-upgrade-to-8-15-2-csv-export-not-working/368902/9 "2024-11-26T10:42:09Z")

</div>

Sorry , can you guide me how to do this?
