# Convert date to string string

**URL:** https://discuss.elastic.co/t/convert-date-to-string-string/181128
**Category:** Logstash
**Created:** [May 15, 2019, 8:45am UTC](https://discuss.elastic.co/t/convert-date-to-string-string/181128 "2019-05-15T08:45:19Z")
**Posts on this page:** 13
**Page:** 1

<div class="post-metadata">

### Author: ![Yoav\_Ben\_Moha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yoav_ben_moha/32/46202_2.png) [@Yoav\_Ben\_Moha](https://discuss.elastic.co/u/Yoav_Ben_Moha)
#### Post date: [May 15, 2019, 8:45am UTC](https://discuss.elastic.co/t/convert-date-to-string-string/181128/1 "2019-05-15T08:45:19Z")

</div>

Hi,  
I am using ELK7 .  
I have a csv file with 3 columns  
I have successfully converted the first two columns from string to integer , but failed to convert  
the 3rd column from string to date.  
In Kibana the 3rd field is still a string

The csv file looks as follow:  
CALLING\_NUMBER,CALLED\_NUMBER,ING\_SIGNAL\_START\_TIME  
61280037234,61262488358,2019-04-18+05:58:10.772  
38580723144,61892967871,2019-04-18+05:58:08.966  
18324621472,23598050505,2019-04-18+05:57:22.294

I have tried to convert the 3rd column as follow:  
filter {  
csv {  
separator =\> ","  
columns =\> ["CALLING\_NUMBER","CALLED\_NUMBER","ING\_SIGNAL\_START\_TIME"]  
}

```
date {
        match => ["ING_SIGNAL_START_TIME", "ISO8601"]
}

mutate { convert => ["CALLING_NUMBER","integer"] }
mutate { convert => ["CALLED_NUMBER","integer"] }

```

}

I have also tried the following option  
date {  
match =\> ["ING\_SIGNAL\_START\_TIME", "YYYY-MM-dd HH:mm:ss.SSS"]  
target =\> "ING\_SIGNAL\_START\_TIME"  
}

None of the option above successded to convert the string to date.

Please advise  
Thanks

---

<div class="post-metadata">

### Author: ![pastechecker](https://avatars.discourse-cdn.com/v4/letter/p/0ea827/32.png) [@pastechecker](https://discuss.elastic.co/u/pastechecker)
#### Post date: [May 15, 2019, 12:28pm UTC](https://discuss.elastic.co/t/convert-date-to-string-string/181128/2 "2019-05-15T12:28:38Z")

</div>

> [@Yoav\_Ben\_Moha](#):
>
> 18324621472,23598050505,2019-04-18+05:57:22.294

There you go:

```
filter {
 csv {
  separator => ","
  columns => ["CALLING_NUMBER","CALLED_NUMBER","ING_SIGNAL_START_TIME"]
 }

#2019-04-18+05:58:10.772
 date {
  match => ["ING_SIGNAL_START_TIME", "yyyy-MM-dd'+'HH:mm:ss.SSS", "MMM dd HH:mm:ss", "ISO8601"]
 }

 mutate { convert => ["CALLING_NUMBER","integer"] }
 mutate { convert => ["CALLED_NUMBER","integer"] }
}

```

**Test data:**  
18324621472,23598050505,2019-04-18+05:57:22.294  
{  
"CALLING\_NUMBER" =\> 18324621472,  
"@version" =\> "1",  
"@timestamp" =\> 2019-04-18T03:57:22.294Z,  
"host" =\> "debugging\_Date",  
"CALLED\_NUMBER" =\> 23598050505,  
"ING\_SIGNAL\_START\_TIME" =\> "2019-04-18+05:57:22.294",  
"message" =\> "18324621472,23598050505,2019-04-18+05:57:22.294"  
}

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [May 15, 2019, 12:28pm UTC](https://discuss.elastic.co/t/convert-date-to-string-string/181128/3 "2019-05-15T12:28:49Z")

</div>

> [@Yoav\_Ben\_Moha](#):
>
> match =\> ["ING\_SIGNAL\_START\_TIME", "YYYY-MM-dd HH:mm:ss.SSS"]

Your field does not have a space between the date and time it has +, so your pattern has to match that

```
match => ["ING_SIGNAL_START_TIME", "YYYY-MM-dd'+'HH:mm:ss.SSS"]

```

---

<div class="post-metadata">

### Author: ![Yoav\_Ben\_Moha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yoav_ben_moha/32/46202_2.png) [@Yoav\_Ben\_Moha](https://discuss.elastic.co/u/Yoav_Ben_Moha)
#### Post date: [May 15, 2019, 7:17pm UTC](https://discuss.elastic.co/t/convert-date-to-string-string/181128/4 "2019-05-15T19:17:54Z")

</div>

Hi,  
I have followed yor suggestion - It didnt help.  
I have insert the data into a new index , but it still didnt converted to date.

```
input {
        file {
                path => "/home/logstash/cdr_files/tst1.csv"
                start_position => "beginning"
                sincedb_path => "/dev/null"
              }
}

filter {
        csv {
                separator => ","
                columns => ["CALLING_NUMBER","CALLED_NUMBER","ING_SIGNAL_START_TIME"]
            }

       date {
              match => ["ING_SIGNAL_START_TIME", "yyyy-MM-dd'+'HH:mm:ss.SSS", "MMM dd HH:mm:ss", "ISO8601"]
            }

        mutate { convert => ["CALLING_NUMBER","integer"] }
        mutate { convert => ["CALLED_NUMBER","integer"] }
}

output {
        elasticsearch {
                        hosts => "localhost"
                        index => "tst100"
                        document_type => "test100_logs"
                      }
        stdout {}
}
```

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [May 15, 2019, 7:23pm UTC](https://discuss.elastic.co/t/convert-date-to-string-string/181128/5 "2019-05-15T19:23:50Z")

</div>

On stdout, do you see ING\_SIGNAL\_START\_TIME as a string, surrounded by quotes, or as a timestamp, like 2019-05-15T14:04:53.879Z? Does the event have a \_dateparsefailure tag?

---

<div class="post-metadata">

### Author: ![Yoav\_Ben\_Moha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yoav_ben_moha/32/46202_2.png) [@Yoav\_Ben\_Moha](https://discuss.elastic.co/u/Yoav_Ben_Moha)
#### Post date: [May 16, 2019, 10:30am UTC](https://discuss.elastic.co/t/convert-date-to-string-string/181128/6 "2019-05-16T10:30:14Z")

</div>

Hi,  
As you ca see bellow ING\_SIGNAL\_START\_TIME apper as a string, surrounded by quotes.

```
{
                 "@version" => "1",
                  "message" => "423115,140407,2019-04-18+05:58:25.209\r",
            "CALLED_NUMBER" => 140407,
                     "path" => "/home/logstash/cdr_files/tst1.csv",
                     "host" => "elk7-lab",
           "CALLING_NUMBER" => 423115,
    "ING_SIGNAL_START_TIME" => "2019-04-18+05:58:25.209",
               "@timestamp" => 2019-04-18T02:58:25.209Z
} 

```

Thanks

---

<div class="post-metadata">

### Author: ![Yoav\_Ben\_Moha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yoav_ben_moha/32/46202_2.png) [@Yoav\_Ben\_Moha](https://discuss.elastic.co/u/Yoav_Ben_Moha)
#### Post date: [May 16, 2019, 12:03pm UTC](https://discuss.elastic.co/t/convert-date-to-string-string/181128/7 "2019-05-16T12:03:28Z")

</div>

I have solve the the problem as follow

```
date {
      match => ["ING_SIGNAL_START_TIME", "YYYY-MM-dd'+'HH:mm:ss.SSS"]
      target => ["newdatetime"]
      remove_field => ["ING_SIGNAL_START_TIME"]
     }

```

And stdout looks ok  
{  
"host" =\> "elk7-lab",  
"CALLING\_NUMBER" =\> 32470,  
"message" =\> "32470,20087,2019-04-18+05:58:39.291\r",  
"@timestamp" =\> 2019-05-16T11:54:49.262Z,  
"path" =\> "/home/logstash/cdr\_files/tst1.csv",  
"CALLED\_NUMBER" =\> 20087,  
"@version" =\> "1",  
"newdatetime" =\> 2019-04-18T02:58:39.291Z  
}

Than i have added few more date fields , but this time the logstatsh failed to run  
date {  
match =\> ["ING\_SIGNAL\_START\_TIME", "YYYY-MM-dd'+'HH:mm:ss.SSS"]  
target =\> ["newdate\_1"]  
remove\_field =\> ["ING\_SIGNAL\_START\_TIME"]

```
        match => ["ING_ADDRESS_COMPLETE_TIME", "YYYY-MM-dd'+'HH:mm:ss.SSS"]
	target => ["newdate_2"]
        remove_field => ["ING_ADDRESS_COMPLETE_TIME"]

        .....

        match => ["EGR_RELEASE_COMPLETE_TIME", "YYYY-MM-dd'+'HH:mm:ss.SSS"]
        target => ["newdate_9"]
        remove_field => ["EGR_RELEASE_COMPLETE_TIME"]	 
    }

```

The error is -  
[INFO] 2019-05-16 15:02:43.870 [LogStash::Runner] runner - Starting Logstash {"logstash.version"=\>"7.0.1"}  
[ERROR] 2019-05-16 15:02:51.331 [Converge PipelineAction::Create] date - Invalid setting for date filter plugin:

filter {  
date {  
# This setting must be a string  
# Expected string, got ["newdate\_1", "newdate\_2", "newdate\_3", "newdate\_4", "newdate\_5", "newdate\_6", "newdate\_7", "newdate\_8", "newdate\_9"]  
target =\> ["newdate\_1", "newdate\_2", "newdate\_3", "newdate\_4", "newdate\_5", "newdate\_6", "newdate\_7", "newdate\_8", "newdate\_9"]  
...  
}  
}  
[ERROR] 2019-05-16 15:02:51.336 [Converge PipelineAction::Create] agent - Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Something is wrong with your configuration.", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/config/mixin.rb:86:in `config_init'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:126:in`initialize'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-date-3.1.9/lib/logstash/filters/date.rb:158:in `initialize'", "org/logstash/plugins/PluginFactoryExt.java:78:in`filter\_delegator'", "org/logstash/plugins/PluginFactoryExt.java:248:in `plugin'", "org/logstash/execution/JavaBasePipelineExt.java:50:in`initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:23:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:36:in`execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:325:in `block in converge\_state'"]}  
[INFO] 2019-05-16 15:02:51.692 [Api Webserver] agent - Successfully started Logstash API endpoint {:port=\>9600}  
[INFO] 2019-05-16 15:02:56.630 [LogStash::Runner] runner - Logstash shut down.

Please advise

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [May 16, 2019, 12:26pm UTC](https://discuss.elastic.co/t/convert-date-to-string-string/181128/8 "2019-05-16T12:26:25Z")

</div>

> [@Yoav\_Ben\_Moha](#):
>
> ```
> "ING_SIGNAL_START_TIME" => "2019-04-18+05:58:25.209",
> "@timestamp" => 2019-04-18T02:58:25.209Z
> 
> ```

Right. You did not set target, so it parsed it into @timestamp.

In your other case, you cannot have multiple match+target pairs in the same date filter. They should be separate filters.

---

<div class="post-metadata">

### Author: ![Yoav\_Ben\_Moha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yoav_ben_moha/32/46202_2.png) [@Yoav\_Ben\_Moha](https://discuss.elastic.co/u/Yoav_Ben_Moha)
#### Post date: [May 16, 2019, 1:09pm UTC](https://discuss.elastic.co/t/convert-date-to-string-string/181128/9 "2019-05-16T13:09:30Z")

</div>

> In your other case, you cannot have multiple match+target pairs in the same date filter. They  
> should be separate filters.

I am sorry, But i didnt understand what i should do if i have several date columns.  
Can you please share a simple test case how to handle such senario ?

Thanks !!!!

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [May 16, 2019, 1:11pm UTC](https://discuss.elastic.co/t/convert-date-to-string-string/181128/10 "2019-05-16T13:11:42Z")

</div>

```
date {
    match => ["ING_SIGNAL_START_TIME", "YYYY-MM-dd'+'HH:mm:ss.SSS"]
    target => ["newdate_1"]
    remove_field => ["ING_SIGNAL_START_TIME"]
}
date {
    match => ["ING_ADDRESS_COMPLETE_TIME", "YYYY-MM-dd'+'HH:mm:ss.SSS"]
    target => ["newdate_2"]
    remove_field => ["ING_ADDRESS_COMPLETE_TIME"]
}
    .....
```

---

<div class="post-metadata">

### Author: ![Yoav\_Ben\_Moha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yoav_ben_moha/32/46202_2.png) [@Yoav\_Ben\_Moha](https://discuss.elastic.co/u/Yoav_Ben_Moha)
#### Post date: [May 16, 2019, 7:47pm UTC](https://discuss.elastic.co/t/convert-date-to-string-string/181128/11 "2019-05-16T19:47:29Z")

</div>

I have folowed the recommanded step .

```auto
date {
    match => ["ING_SIGNAL_START_TIME", "YYYY-MM-dd'+'HH:mm:ss.SSS"]
    target => ["newdate_1"]
    remove_field => ["ING_SIGNAL_START_TIME"]
}
date {
    match => ["ING_ADDRESS_COMPLETE_TIME", "YYYY-MM-dd'+'HH:mm:ss.SSS"]
    target => ["newdate_2"]
    remove_field => ["ING_ADDRESS_COMPLETE_TIME"]

```

All the columns which marked as removed\_field=\> .... Did NOT removed , and actually all the date fields are still appear as Strings.  
In the stdout i dont see the "newdate\_xx" fields

Example

....  
"CALLED\_NUMBER" =\> 4478,  
"EGR\_CALL\_RELEASE\_TIME" =\> "04/18/2019 05:58:38",  
"ING\_CALL\_ANSWER\_TIME" =\> "04/18/2019 05:58:36",  
"ING\_RELEASE\_COMPLETE\_TIME" =\> "04/18/2019 05:58:38",  
....  
"@version" =\> "1",  
}  
{  
"tags" =\> [  
[0] "\_dateparsefailure"  
],

Any advise ... ?

Thanks

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [May 16, 2019, 7:57pm UTC](https://discuss.elastic.co/t/convert-date-to-string-string/181128/12 "2019-05-16T19:57:08Z")

</div>

> [@Yoav\_Ben\_Moha](#):
>
> "04/18/2019 05:58:38"

That does not match "YYYY-MM-dd'+'HH:mm:ss.SSS" do your different filters have different formats? Did you change the format of the data being input?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 13, 2019, 7:57pm UTC](https://discuss.elastic.co/t/convert-date-to-string-string/181128/13 "2019-06-13T19:57:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
