# Cisco Module/Meraki not properly parsing date on all events

**URL:** <https://discuss.elastic.co/t/cisco-module-meraki-not-properly-parsing-date-on-all-events/257584>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 3, 2020, 8:29pm UTC](https://discuss.elastic.co/t/cisco-module-meraki-not-properly-parsing-date-on-all-events/257584 "2020-12-03T20:29:49Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![justinainsworth](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justinainsworth/32/78782_2.png) [@justinainsworth](https://discuss.elastic.co/u/justinainsworth)\
**Post date:** [December 3, 2020, 8:29pm UTC](https://discuss.elastic.co/t/cisco-module-meraki-not-properly-parsing-date-on-all-events/257584/1 "2020-12-03T20:29:49Z")

</div>

I've been playing around with the new Meraki fileset in the Cisco module, and have noticed that for some event types, the date is not properly parsed, and i get a @timestamp of '1970-01-01T00:00:03.000Z'. Here is a sample original log entry:

```auto
Dec 3 12:03:30 HOSTNAME 1 1607025810.308975186 HOSTNAME events type=disassociation radio='1' vap='3' client_mac='00:00:00:00:00:00' channel='48' reason='4' duration='362.778560402' auth_neg_dur='0.003999999' last_auth_ago='362.758560400' is_wpa='1' arp_resp='29.995999997' arp_src='1.2.3.4' aid='1291454018'

```

from what i have noticed, it is when 'events' follows the hostname. other type of events (flows, etc.) parse successfully.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 31, 2020, 10:30pm UTC](https://discuss.elastic.co/t/cisco-module-meraki-not-properly-parsing-date-on-all-events/257584/2 "2020-12-31T22:30:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
