# Apache Error logs timestamp

**URL:** https://discuss.elastic.co/t/apache-error-logs-timestamp/82010
**Category:** Logstash
**Created:** [April 11, 2017, 3:30pm UTC](https://discuss.elastic.co/t/apache-error-logs-timestamp/82010 "2017-04-11T15:30:41Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![mkorayem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mkorayem/32/85774_2.png) [@mkorayem](https://discuss.elastic.co/u/mkorayem)
#### Post date: [April 11, 2017, 3:30pm UTC](https://discuss.elastic.co/t/apache-error-logs-timestamp/82010/1 "2017-04-11T15:30:41Z")

</div>

Hi

I tried to get the pattern for apache error timestamp but all failed

The timestamp is used in elasticsearch is when it is indexed not the time of the error

 ![](https://us1.discourse-cdn.com/elastic/original/3X/8/0/80047e7c27d67680da0bef00c56c728b21ab2cad.png)

e.g.  
[Sun Feb 05 00:32:24.992868 2017] [mpm\_winnt:notice] [pid 8776:tid 168] AH00354: Child: Starting 150 worker threads., Child: Starting 150 worker threads

and when I search for timestamp in the index pattern I find this:

Multiple timestamp with different types: date and string

 ![](https://us1.discourse-cdn.com/elastic/original/3X/6/7/677edc75ae0263e1ff24f16e5385fe65eabd0a80.png)

###########################################################

# 

# This is the logstash config filter part

# 

###########################################################  
filter {  
if [type] == "syslog"  
{  
mutate { add\_tag =\> "syslog\_tag" }  
grok  
{  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
syslog\_pri { }  
date  
{  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
#The winlogbeat send it as wineventlog and logstash put it automatically in winlogevent index

# No need for special configuration here

####################################################################################

# if [type] == "wineventlog"

# {

# grok

# {

# match =\> { "TimeCreated", "Date(%{NUMBER:timestamp})" }

# }

# date

# {

# match =\> ["timestamp", "UNIX\_MS"]

# }

# }

####################################################################################  
if [type] == "apache\_access"  
{  
grok  
{  
match =\> { "message" =\> ["%{COMBINEDAPACHELOG}", "%{IPORHOST:clientip} %{NOTSPACE:ident} %{NOTSPACE:auth} [%{HTTPDATE:timestamp}] "(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion}))" %{NOTSPACE:response} (?:%{NOTSPACE:bytes})" ] }  
}  
date  
{  
match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]  
}  
}  
if [type] == "apache\_error"  
{  
grok  
{  
match =\> { "message" =\> "[(?%{DAY:day} %{MONTH:month} %{MONTHDAY} %{TIME} %{YEAR})] [%{WORD:module}:%{LOGLEVEL:loglevel}] [pid %{NUMBER:pid}:tid %{NUMBER:tid}]( (%{POSINT:proxy\_errorcode})%{DATA:proxy\_errormessage}:)?( [client %{IPORHOST:client}:%{POSINT:clientport}])? %{DATA:errorcode}: %{GREEDYDATA:message}" }  
}  
date  
{  
match =\> ["timestamp" , "EEE MMM dd HH:mm:ssssss yyyy"]  
}  
}  
if [type] == "apache\_sslrequest"  
{  
grok  
{  
match =\> { "message" =\> "[%{HTTPDATE:timestamp}] %{IPORHOST:client} %{NOTSPACE:protocol} %{NOTSPACE:cipher} "(%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})" }  
}  
date  
{  
match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]  
}  
}  
}

---

<div class="post-metadata">

### Author: ![rabbit](https://avatars.discourse-cdn.com/v4/letter/r/919ad9/32.png) [@rabbit](https://discuss.elastic.co/u/rabbit)
#### Post date: [April 11, 2017, 4:06pm UTC](https://discuss.elastic.co/t/apache-error-logs-timestamp/82010/2 "2017-04-11T16:06:32Z")

</div>

improve your question please.

1. I think your field named "timestamp" is not been recognized as one, you need to see if the date in your logs is really a TimeStamp that is following a specific pattern.
2. To use the Date in your logs as the "Time" Field in Kibana, you will need to Identify the timestamp field in the moment that you create your index in kibana management ui.

---

<div class="post-metadata">

### Author: ![mkorayem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mkorayem/32/85774_2.png) [@mkorayem](https://discuss.elastic.co/u/mkorayem)
#### Post date: [April 11, 2017, 5:35pm UTC](https://discuss.elastic.co/t/apache-error-logs-timestamp/82010/3 "2017-04-11T17:35:24Z")

</div>

This is the date from the apache error log

[Sun Feb 05 00:32:24.992868 2017]

And when I create the index, I chose the timestamp field to be used but still no luck

---

<div class="post-metadata">

### Author: ![jkuang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jkuang/32/72637_2.png) [@jkuang](https://discuss.elastic.co/u/jkuang)
#### Post date: [April 11, 2017, 6:21pm UTC](https://discuss.elastic.co/t/apache-error-logs-timestamp/82010/4 "2017-04-11T18:21:16Z")

</div>

I believe what you're asking is how to update the @timestamp to the date time your error occurred. The reason you have multiple timestamp is because you declared a timestamp variable.

Take a look at the discussion below:

> [@Parsing Log With grok Filter](https://discuss.elastic.co/t/parsing-log-with-grok-filter/81162/9):
>
> The example I provided early did it exactly for me. Output { "path" =\> "/tmp/time.data", "@timestamp" =\> 2017-03-24T09:01:43.541Z, "@version" =\> "1", "host" =\> "JImmys-MacBook-Pro.local", "message" =\> "2017-03-24T09:01:43.541", "type" =\> "apache-access", "event\_timestamp" =\> "2017-03-24T09:01:43.541Z" }

---

<div class="post-metadata">

### Author: ![mkorayem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mkorayem/32/85774_2.png) [@mkorayem](https://discuss.elastic.co/u/mkorayem)
#### Post date: [April 12, 2017, 7:28am UTC](https://discuss.elastic.co/t/apache-error-logs-timestamp/82010/5 "2017-04-12T07:28:31Z")

</div>

Hi Jimmy,

I declared a different variable "mytimestamp" and used the date filter to assign it to the @timestamp but still with no luck.

From what I see in the discussions and documentation, this should be straight forward !

```
    if [type] == "apache_error"
    {
            grok
            {
                    match => { "message" => "\[(?<mytimestamp>%{DAY:day} %{MONTH:month} %{MONTHDAY} %{TIME} %{YEAR})\] \[%{WORD:module}:%{LOGLEVEL:loglevel}\] \[pid %{NUMBER:pid}:tid %{NUMBER:tid}\]( \(%{POSINT:proxy_errorcode}\)%{DATA:proxy_errormessage}:)?( \[client %{IPORHOST:client}:%{POSINT:clientport}\])? %{DATA:errorcode}: %{GREEDYDATA:message}" }
            }
            date
            {
                    match => ["mytimestamp" , "EEE MMM dd HH:mm:ssssss yyyy"]
            }
    }
```

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [April 12, 2017, 7:32am UTC](https://discuss.elastic.co/t/apache-error-logs-timestamp/82010/6 "2017-04-12T07:32:20Z")

</div>

Please show an example of an event that has been processed with those filters. Please copy/paste from Kibana's JSON tab instead of posting a screenshot.

---

<div class="post-metadata">

### Author: ![mkorayem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mkorayem/32/85774_2.png) [@mkorayem](https://discuss.elastic.co/u/mkorayem)
#### Post date: [April 12, 2017, 7:45am UTC](https://discuss.elastic.co/t/apache-error-logs-timestamp/82010/7 "2017-04-12T07:45:03Z")

</div>

Here it is

{  
"\_index": "apache-2017.04.11",  
"\_type": "apache\_error",  
"\_id": "AVtdmOC-wb2d0\_A3HR5q",  
"\_score": null,  
"\_source": {  
"offset": 19187,  
"module": "core",  
"input\_type": "log",  
"pid": "1056",  
"source": "C:\xampp\apache\logs\error.log",  
"message": [  
"[Mon Feb 27 10:59:12.930694 2017] [core:notice] [pid 1056:tid 528] AH00094: Command line: 'c:\\xampp\\apache\\bin\\httpd.exe -d C:/xampp/apache'",  
"Command line: 'c:\\xampp\\apache\\bin\\httpd.exe -d C:/xampp/apache'"  
],  
"type": "apache\_error",  
"tid": "528",  
"tags": [  
"beats\_input\_codec\_plain\_applied",  
"\_dateparsefailure"  
],  
"@timestamp": "2017-04-11T15:18:54.132Z",  
"month": "Feb",  
"mytimestamp": "Mon Feb 27 10:59:12.930694 2017",  
"loglevel": "notice",  
"@version": "1",  
"beat": {  
"hostname": "services",  
"name": "services",  
"version": "5.2.2"  
},  
"host": "services",  
"fields": {  
"logtype": "apache"  
},  
"day": "Mon",  
"errorcode": "AH00094"  
},  
"fields": {  
"@timestamp": [  
1491923934132  
]  
},  
"highlight": {  
"source": [  
"@kibana-highlighted-field@C@/kibana-highlighted-field@:\@kibana-highlighted-field@xampp@/kibana-highlighted-field@\@kibana-highlighted-field@apache@/kibana-highlighted-field@\@kibana-highlighted-field@logs@/kibana-highlighted-field@\@kibana-highlighted-field@error.log@/kibana-highlighted-field@"  
]  
},  
"sort": [  
1491923934132  
]  
}

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [April 12, 2017, 8:21am UTC](https://discuss.elastic.co/t/apache-error-logs-timestamp/82010/8 "2017-04-12T08:21:31Z")

</div>

The `_dateparsefailure` tag indicates that the date filter failed. Read Logstash's log to find out why.

---

<div class="post-metadata">

### Author: ![mkorayem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mkorayem/32/85774_2.png) [@mkorayem](https://discuss.elastic.co/u/mkorayem)
#### Post date: [April 12, 2017, 9:12am UTC](https://discuss.elastic.co/t/apache-error-logs-timestamp/82010/9 "2017-04-12T09:12:36Z")

</div>

I made the logstash logging as debug and this is what I got, I do not see any error

@timestamp"=\>2017-04-12T08:43:30.624Z !!

# ====================================================================== LOG

[2017-04-12T10:43:00,859][DEBUG][logstash.filters.date] config LogStash::Filters::Date/@tag\_on\_failure = ["\_dateparsefailure"]  
[2017-04-12T10:43:00,859][DEBUG][org.logstash.filters.DateFilter] Date filter with format=EEE MMM dd HH:mm:ss,SSS yyyy, locale=null, timezone=null built as org.logstash.filters.parser.JodaParser

[2017-04-12T10:43:31,078][DEBUG][logstash.pipeline] filter received {"event"=\>{"@timestamp"=\>2017-04-12T08:43:30.624Z, "offset"=\>168, "@version"=\>"1", "input\_type"=\>"log", "beat"=\>{"hostname"=\>"services", "name"=\>"services", "version"=\>"5.2.2"}, "host"=\>"services", "source"=\>"C:\xampp\apache\logs\error.log", "message"=\>"[Thu Oct 13 08:24:05.627280 2016] [ssl:warn] [pid 6772:tid 172] AH01909: www.example.com:443:0 server certificate does NOT include an ID which matches the server name", "fields"=\>{"logtype"=\>"apache"}, "type"=\>"apache\_error", "tags"=\>["beats\_input\_codec\_plain\_applied"]}}

[2017-04-12T10:43:31,078][DEBUG][logstash.filters.grok] Running grok filter {:event=\>2017-04-12T08:43:30.624Z services [Thu Oct 13 08:24:05.627280 2016] [ssl:warn] [pid 6772:tid 172] AH01909: www.example.com:443:0 server certificate does NOT include an ID which matches the server name}

[2017-04-12T10:43:31,078][DEBUG][logstash.filters.grok] Event now: {:event=\>2017-04-12T08:43:30.624Z services [Thu Oct 13 08:24:05.627280 2016] [ssl:warn] [pid 6772:tid 172] AH01909: www.example.com:443:0 server certificate does NOT include an ID which matches the server name,www.example.com:443:0 server certificate does NOT include an ID which matches the server name}

[2017-04-12T10:43:31,084][DEBUG][logstash.pipeline] output received {"event"=\>{"offset"=\>168, "module"=\>"ssl", "input\_type"=\>"log", "pid"=\>"6772", "source"=\>"C:\xampp\apache\logs\error.log", "message"=\>["[Thu Oct 13 08:24:05.627280 2016] [ssl:warn] [pid 6772:tid 172] AH01909: www.example.com:443:0 server certificate does NOT include an ID which matches the server name", "www.example.com:443:0 server certificate does NOT include an ID which matches the server name"], "type"=\>"apache\_error", "tid"=\>"172", "tags"=\>["beats\_input\_codec\_plain\_applied", "\_dateparsefailure"], "@timestamp"=\>2017-04-12T08:43:30.624Z, "loglevel"=\>"warn", "@version"=\>"1", "beat"=\>{"hostname"=\>"services", "name"=\>"services", "version"=\>"5.2.2"}, "host"=\>"services", "fields"=\>{"logtype"=\>"apache"}, "errorcode"=\>"AH01909", "timestamp"=\>"Thu Oct 13 08:24:05.627280 2016"}}

---

<div class="post-metadata">

### Author: ![mkorayem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mkorayem/32/85774_2.png) [@mkorayem](https://discuss.elastic.co/u/mkorayem)
#### Post date: [April 12, 2017, 9:43am UTC](https://discuss.elastic.co/t/apache-error-logs-timestamp/82010/10 "2017-04-12T09:43:59Z")

</div>

I found the issue.

It is because of the date format in the date filter

I used "," instead of "." and use SSS intead of SSSSSS

And in case you do not need these milli or micro seconds you can use the gsub to remove the 6 or 3 numbers after the . before you give it to the date filter

--

Thanks all for your help

```
            mutate
            {
                   gsub => ["timestamp", "\.\d{6}", ""]
            }

            date
            {
                    match => ["timestamp" , "EEE MMM dd HH:mm:ss.SSSSSS yyyy"]
            }
```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 10, 2017, 9:48am UTC](https://discuss.elastic.co/t/apache-error-logs-timestamp/82010/11 "2017-05-10T09:48:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
