# Convert text field to date in ingest pipeline

**URL:** <https://discuss.elastic.co/t/convert-text-field-to-date-in-ingest-pipeline/332595>\
**Category:** Elasticsearch\
**Tags:** ingest-pipeline\
**Created:** [May 4, 2023, 7:55pm UTC](https://discuss.elastic.co/t/convert-text-field-to-date-in-ingest-pipeline/332595 "2023-05-04T19:55:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![KentLee](https://avatars.discourse-cdn.com/v4/letter/k/e274bd/32.png) [@KentLee](https://discuss.elastic.co/u/KentLee)\
**Post date:** [May 4, 2023, 7:55pm UTC](https://discuss.elastic.co/t/convert-text-field-to-date-in-ingest-pipeline/332595/1 "2023-05-04T19:55:41Z")

</div>

Hi,  
I am creating a ingest pipeline to ingest application log to elastic and I have the log line format as follow:  
[2023-05-03 16:12:19,420] - [Application Name] - [INFO] - Log details goes here

Based on this format I created an ingest pipeline with grok processor:  
\[%{TIMESTAMP\_ISO8601:log.timestamp}\] - \[%{DATA:log.appName}\] - \[%{DATA:log.level}\] %{GREEDYDATA:log.message}.

It's working fine. However, I wanted to convert the field log.timestamp (which is a text field) to date, and the date processor shows "error"

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/7/977f5720fa0c922d78171caff533ecd90756f414.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/0/2003e911adf3cd7a26201a5df8a33cb186463250.png)

---

<div class="post-metadata">

**Author:** ![Priscilla\_Parodi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priscilla_parodi/32/43047_2.png) [@Priscilla\_Parodi](https://discuss.elastic.co/u/Priscilla_Parodi)\
**Post date:** [May 4, 2023, 11:16pm UTC](https://discuss.elastic.co/t/convert-text-field-to-date-in-ingest-pipeline/332595/2 "2023-05-04T23:16:26Z")

</div>

Hello KentLee,

Probably because the text field containing log dates **2023-05-03 16:12:19,420** does not match the date format `["yyyy-MM-dd HH:mm:ss.SSS"]`

Try to use this `yyyy-MM-dd HH:mm:ss,SSS` in the Formats.

Hope it helps.

---

<div class="post-metadata">

**Author:** ![KentLee](https://avatars.discourse-cdn.com/v4/letter/k/e274bd/32.png) [@KentLee](https://discuss.elastic.co/u/KentLee)\
**Post date:** [May 5, 2023, 12:59pm UTC](https://discuss.elastic.co/t/convert-text-field-to-date-in-ingest-pipeline/332595/3 "2023-05-05T12:59:25Z")

</div>

> [@Priscilla\_Parodi](#):
>
> `yyyy-MM-dd HH:mm:ss,SSS`

Thank you, it works.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2023, 6:02am UTC](https://discuss.elastic.co/t/convert-text-field-to-date-in-ingest-pipeline/332595/5 "2023-06-05T06:02:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
