# Bug in pipeline date filter

**URL:** <https://discuss.elastic.co/t/bug-in-pipeline-date-filter/236234>\
**Category:** Elasticsearch\
**Created:** [June 8, 2020, 8:59pm UTC](https://discuss.elastic.co/t/bug-in-pipeline-date-filter/236234 "2020-06-08T20:59:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Richard\_Neely](https://avatars.discourse-cdn.com/v4/letter/r/90db22/32.png) [@Richard\_Neely](https://discuss.elastic.co/u/Richard_Neely)\
**Post date:** [June 8, 2020, 8:59pm UTC](https://discuss.elastic.co/t/bug-in-pipeline-date-filter/236234/1 "2020-06-08T20:59:45Z")

</div>

Trying to parse some zookeeper logs as below but no matter the month in the timestamp it is always set to 01 and never gets ingested.

##Sample simulate.

```auto
    {
      "docs": [
        {
          "_index": "filebeat-7.7.0-2020-06.08",
          "_id": "id",
          "_source": {
            "message": "2020-06-08 16:27:05,962 [myid:5] - INFO [NIOServerCxn.Factory:0.0.0.0/0.0.0.0:2181:NIOServerCnxn@1056] - Closed socket connection for client /10.0.0.1:48520 (no session established for client)"
          }
        }
      ]
    }

```

##Date filter i'm using.

```auto
    {
            "date" : {
              "field" : "timestamp",
              "target_field" : "@timestamp",
              "ignore_failure": true, 
              "formats" : [
                "yyyy-MM-DD HH:mm:ss,SSS"
              ],
              "on_failure" : [
                {
                  "append" : {
                    "field" : "error.message",
                    "value" : "{{ _ingest.on_failure_message }}"
                  }
                }
              ]
            }
          },
          {
            "remove" : {
              "field" : "timestamp"
            }
          }
        ],

```

##Output showing the month as 01 when it should be 06.

```auto
    {
      "docs" : [
        {
          "doc" : {
            "_index" : "filebeat-7.7.0-2020-06.08",
            "_type" : "_doc",
            "_id" : "id",
            "_source" : {
              "metadata" : "NIOServerCxn.Factory:0.0.0.0/0.0.0.0:2181:NIOServerCnxn@1056",
              "@timestamp" : "2020-01-08T16:27:05.962Z",
              "myid" : "5",
              "level" : "INFO",
              "program" : "zookeeper",
              "message" : "Closed socket connection for client /10.0.0.1:48520 (no session established for client)"
            },
            "_ingest" : {
              "timestamp" : "2020-06-08T20:53:38.277911Z"
            }
          }
        }
      ]
    }

```

---

<div class="post-metadata">

**Author:** ![Richard\_Neely](https://avatars.discourse-cdn.com/v4/letter/r/90db22/32.png) [@Richard\_Neely](https://discuss.elastic.co/u/Richard_Neely)\
**Post date:** [June 11, 2020, 2:21pm UTC](https://discuss.elastic.co/t/bug-in-pipeline-date-filter/236234/2 "2020-06-11T14:21:35Z")

</div>

I figured this out. I had DD and dd mixed up.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 12, 2020, 11:38pm UTC](https://discuss.elastic.co/t/bug-in-pipeline-date-filter/236234/3 "2020-07-12T23:38:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
