# Convert String to date and compare it

**URL:** <https://discuss.elastic.co/t/convert-string-to-date-and-compare-it/311394>\
**Category:** Logstash\
**Created:** [August 4, 2022, 10:10am UTC](https://discuss.elastic.co/t/convert-string-to-date-and-compare-it/311394 "2022-08-04T10:10:54Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![alex\_vermex](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_vermex/32/101267_2.png) [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Post date:** [August 4, 2022, 10:10am UTC](https://discuss.elastic.co/t/convert-string-to-date-and-compare-it/311394/1 "2022-08-04T10:10:54Z")

</div>

Hi,  
I have two fields and I want to compare it

- field1: 20220720091723
- field2: 07/20/22 09:17  
I want to compare it so i don't know if i should convert to date then compare and how or can someone please tell me what i should do

Thanks!

---

<div class="post-metadata">

**Author:** ![alex\_vermex](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_vermex/32/101267_2.png) [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Post date:** [August 4, 2022, 11:49am UTC](https://discuss.elastic.co/t/convert-string-to-date-and-compare-it/311394/2 "2022-08-04T11:49:32Z")

</div>

i tryed this in logstash :

```auto
date {
        match => ["field1", "yyyyMMddHHmmss"]
      }

```

but still doesn't work it stays String... and if I convert these two fields so I can compare it, right?

---

<div class="post-metadata">

**Author:** ![alex\_vermex](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_vermex/32/101267_2.png) [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Post date:** [August 4, 2022, 2:30pm UTC](https://discuss.elastic.co/t/convert-string-to-date-and-compare-it/311394/3 "2022-08-04T14:30:58Z")

</div>

I think i found the solution but there is somthing wrong

```auto
date {
        match => ["field1", "yyyyMMddHHmmss"]
        target => "field1"
      }
date {
        match => ["field2", "dd/MM/yy HH:mm"]
        target => "field2"
      }

```

output:

- field1: 2022-07-20T09:24:07.000Z
- field2: 2022-07-20T05:06:00.000Z  
Can I specify the output format? for example I just want to keep yyyy-MM-DD HH:mm because the first field contains the ss and field2 just mm

Any help would be sincerely appreciate!  
Thanks!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 4, 2022, 4:00pm UTC](https://discuss.elastic.co/t/convert-string-to-date-and-compare-it/311394/4 "2022-08-04T16:00:35Z")

</div>

> [@alex\_vermex](#):
>
> Can I specify the output format?

Maybe. See [this](https://discuss.elastic.co/t/date-field-being-converted-to-timestamps/180044/2) thread.

---

<div class="post-metadata">

**Author:** ![alex\_vermex](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_vermex/32/101267_2.png) [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Post date:** [August 4, 2022, 8:16pm UTC](https://discuss.elastic.co/t/convert-string-to-date-and-compare-it/311394/5 "2022-08-04T20:16:25Z")

</div>

Thanks for the reply  
there is a little thing that i don't understand here the original field `20220720185907` after matching and target ... it looks like this now `field1: 2022-07-20T17:59:07.000Z` it was changed for one hour honestly i don't know why.  
after ruby filter and thanks for this it gives me `someField000: 2022-07-20 18:07`  
ruby filter :

```auto
ruby {
        code => '
            t = Time.at(event.get("Date Transmission").to_f)
            event.set("someField", t.strftime("%Y-%m-%d"))
            event.set("someField000", t.strftime("%Y-%m-%d %H:%m"))
        '
    }

```

But I specified the minute not the second. did i do something wrong ?  
Thanks!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 4, 2022, 8:51pm UTC](https://discuss.elastic.co/t/convert-string-to-date-and-compare-it/311394/6 "2022-08-04T20:51:30Z")

</div>

> [@alex\_vermex](#):
>
> it was changed for one hour honestly i don't know why

When you parse a string with a date filter the result is always in UTC (note the Z at the end of [field1]. Is the timezone of the machine running logstash one hour ahead of UTC, as much of Europe is?

---

<div class="post-metadata">

**Author:** ![alex\_vermex](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_vermex/32/101267_2.png) [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Post date:** [August 5, 2022, 7:21am UTC](https://discuss.elastic.co/t/convert-string-to-date-and-compare-it/311394/7 "2022-08-05T07:21:13Z")

</div>

Yes ok thanks, just about the ruby filter `event.set("someField000", t.strftime("%Y-%m-%d %H:%m"))` I specified the minute not the second and it gives me `someField000: 2022-07-20 18:07` there is somthing wrong right ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 5, 2022, 2:34pm UTC](https://discuss.elastic.co/t/convert-string-to-date-and-compare-it/311394/8 "2022-08-05T14:34:06Z")

</div>

Looks OK to me. Why do you think it is wrong?

---

<div class="post-metadata">

**Author:** ![alex\_vermex](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_vermex/32/101267_2.png) [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Post date:** [August 7, 2022, 8:49am UTC](https://discuss.elastic.co/t/convert-string-to-date-and-compare-it/311394/9 "2022-08-07T08:49:21Z")

</div>

I mean it should give me `someField000:2022-07-20 18:59` not `someField000:2022-07-20 18:07` i specified `%H:%m` not `%H: %s` no?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 7, 2022, 4:41pm UTC](https://discuss.elastic.co/t/convert-string-to-date-and-compare-it/311394/10 "2022-08-07T16:41:14Z")

</div>

`%H:%m` is hour and month, not hour and minute. Try `%H:%M`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 4, 2022, 4:41pm UTC](https://discuss.elastic.co/t/convert-string-to-date-and-compare-it/311394/11 "2022-09-04T16:41:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
