# Cannot parse empty date

**URL:** <https://discuss.elastic.co/t/cannot-parse-empty-date/320575>\
**Category:** Logstash\
**Created:** [December 6, 2022, 12:17pm UTC](https://discuss.elastic.co/t/cannot-parse-empty-date/320575 "2022-12-06T12:17:10Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![stefanocog](https://avatars.discourse-cdn.com/v4/letter/s/5fc32e/32.png) [@stefanocog](https://discuss.elastic.co/u/stefanocog)\
**Post date:** [December 6, 2022, 12:17pm UTC](https://discuss.elastic.co/t/cannot-parse-empty-date/320575/1 "2022-12-06T12:17:10Z")

</div>

Hi, I have a log that has a json field inside that can have empty fields, specifically I have a `date` field, the log can be like this

> "2022-11-28 09:24:46:705"|"+0100"|"transId: xxxxxx"|"resId: xxxxxx"|"1.1.1.1"|"[https://example.com/xxxxxx"|"HTTP/1.1"|"EXE"|"GET"|"404"|"](https://example.com/xxxxxx%22%7C%22HTTP/1.1%22%7C%22EXE%22%7C%22GET%22%7C%22404%22%7C%22){"codCpi":"","codFis": "","codSap": "","codState": "","datBirth": "", "xml": ""}"|"token : xxxx"

Have this rule for match:

```auto
filter {
  grok {
    match => { "message" => "\"%{TIMESTAMP_ISO8601:timestamp}\"\|\"%{DATA:tz}\"\|\"transId: %{GREEDYDATA:transactionId}\"\|\"resId: %{GREEDYDATA:responseId}\"\|\"%{IP:ip}\"\|\"%{GREEDYDATA:url}\"\|\"%{DATA:httpver}\"\|\"%{DATA:exe}\"\|\"%{WORD:httpverb}\"\|\"%{GREEDYDATA:httpCodeResponse}\"\|\"%{DATA:contentRequest}\"\|\"%{GREEDYDATA:token}\"" }
  }
  json {
    source => "contentRequest"
  }
}

```

With this match i have this error:

> "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field [datBirth] of type [date] in document with id 'VSFI54QBv1ziCbBLadWr'. Preview of field's value: ''", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"cannot parse empty date"}}}}

Instead, there is no error if the field `datBirth` is filled in

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [December 6, 2022, 12:45pm UTC](https://discuss.elastic.co/t/cannot-parse-empty-date/320575/2 "2022-12-06T12:45:51Z")

</div>

To confirm, are you only receiving this error for events where `datBirth` is empty, and parsing is successful when it's populated?

If so you could try specifying zero or one occurrences using the ? operator, as per the below:

> [@Making a part in the grok expression optional](https://discuss.elastic.co/t/making-a-part-in-the-grok-expression-optional/43961):
>
> Hi all, Each line in my log file does not contain a source IP adderss so the "message" =\> "%{TIMESTAMP\_ISO8601:timestamp}\s+%{LOGLEVEL:loglevel}\s+%{THREAD:thread}\s+(?:%{IP:ip})" so it returns a "no mach" - from grok debugger. As result the the fields that I'm expecting to be created by the grok{} is not happening. So we tried to make the pattern for IP in this expression something like : match =\> {"message" =\> "%{TIMESTAMP\_ISO8601:timestamp}\s+%{LOGLEVEL:loglevel}\s+%{THREAD:thread}…

---

<div class="post-metadata">

**Author:** ![stefanocog](https://avatars.discourse-cdn.com/v4/letter/s/5fc32e/32.png) [@stefanocog](https://discuss.elastic.co/u/stefanocog)\
**Post date:** [December 6, 2022, 12:55pm UTC](https://discuss.elastic.co/t/cannot-parse-empty-date/320575/3 "2022-12-06T12:55:56Z")

</div>

I confirm that if the field is filled in, it works.  
Unfortunately it is a service of which I have no control, I don't think it can be changed

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [December 6, 2022, 12:58pm UTC](https://discuss.elastic.co/t/cannot-parse-empty-date/320575/4 "2022-12-06T12:58:28Z")

</div>

You can remove the field if it is empty.

```auto
if [dateBirth] == "" {
    mutate {
        remove_field => ["dateBirth"]
    }
}

```

---

<div class="post-metadata">

**Author:** ![stefanocog](https://avatars.discourse-cdn.com/v4/letter/s/5fc32e/32.png) [@stefanocog](https://discuss.elastic.co/u/stefanocog)\
**Post date:** [December 6, 2022, 1:16pm UTC](https://discuss.elastic.co/t/cannot-parse-empty-date/320575/5 "2022-12-06T13:16:58Z")

</div>

Sorry I did not understand 😀  
Seems to work with this rule

```auto
filter {
  grok {
    match => { "message" => "\"%{TIMESTAMP_ISO8601:timestamp}\"\|\"%{DATA:tz}\"\|\"transId: %{GREEDYDATA:transactionId}\"\|\"resId: %{GREEDYDATA:responseId}\"\|\"%{IP:ip}\"\|\"%{GREEDYDATA:url}sap/API/SAP/codFiscale\/%{GREEDYDATA:codicefiscale}\"\|\"%{DATA:httpver}\"\|\"%{DATA:gruppo}\"\|\"%{WORD:httpverb}\"\|\"%{GREEDYDATA:httpCodeResponse}\"\|\"(?<contentRequest>{.*})\"\|\"%{GREEDYDATA:token}\"" }
  }
  json {
    source => "contentRequest"
  }
}

```

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 3, 2023, 1:17pm UTC](https://discuss.elastic.co/t/cannot-parse-empty-date/320575/6 "2023-01-03T13:17:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
