# Create Grok filter date

**URL:** <https://discuss.elastic.co/t/create-grok-filter-date/222285>\
**Category:** Logstash\
**Created:** [March 5, 2020, 12:27pm UTC](https://discuss.elastic.co/t/create-grok-filter-date/222285 "2020-03-05T12:27:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![dbviz](https://avatars.discourse-cdn.com/v4/letter/d/e19b73/32.png) [@dbviz](https://discuss.elastic.co/u/dbviz)\
**Post date:** [March 5, 2020, 12:27pm UTC](https://discuss.elastic.co/t/create-grok-filter-date/222285/1 "2020-03-05T12:27:59Z")

</div>

Hi everyone,

I tried to parse date from this line

> Wed Nov 27 07:31:40 CET 2019;User123;NEWPORT.WEBSERVICE.EXAMPLE

like that in grok filter

```
		grok { 
			match => {"message" => ["%{GREEDYDATA:date};%{USER:user};%{GREEDYDATA:webservice}"] } 
		}
		date {
				match => ["date", "EEE MMM dd HH:mm:ss z yyyy"]
			}
	}

```

The parsing works but not for date field, I have this result

> {  
> "@version" =\> "1",  
> "user" =\> "User123",  
> "type" =\> "txt",  
> "date" =\> "Wed Nov 27 07:31:40 CET 2019",  
> "webservice" =\> "NEWPORT.WEBSERVICE.EXAMPLE",  
> "host" =\> "host12",  
> "tags" =\> [  
> [0] "\_dateparsefailure"  
> ],  
> "path" =\> "a/logs/7.txt",  
> "message" =\> "Wed Nov 27 07:31:40 CET 2019;User123;NEWPORT.WEBSERVICE.EXAMPLE",  
> "@timestamp" =\> 2020-03-05T12:17:08.007Z  
> }

Someone know if the problem comes from the date parse ?

Thank you

---

<div class="post-metadata">

**Author:** ![dbviz](https://avatars.discourse-cdn.com/v4/letter/d/e19b73/32.png) [@dbviz](https://discuss.elastic.co/u/dbviz)\
**Post date:** [March 6, 2020, 12:51pm UTC](https://discuss.elastic.co/t/create-grok-filter-date/222285/2 "2020-03-06T12:51:40Z")

</div>

I have tried this grok :

```
grok { 
	match => {"message" => "%{SYSLOGTIMESTAMP:syslog}%{SPACE}%{DATA:zone}%{YEAR:syslog};%{USER:user};%{GREEDYDATA:webservice}"} 
}

```

The output is now but can't convert in timestamp :

```
  "syslog" => [
         [0] "Nov 22 12:37:51",
         [1] "2019"
    ]
```

---

<div class="post-metadata">

**Author:** ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)\
**Post date:** [March 6, 2020, 1:52pm UTC](https://discuss.elastic.co/t/create-grok-filter-date/222285/3 "2020-03-06T13:52:58Z")

</div>

> [@dbviz](#):
>
> Wed Nov 27 07:31:40 CET 2019;User123;NEWPORT.WEBSERVICE.EXAMPLE

Hi there,

the problem is the following (reported in the documentation)

> z time zone names. **Time zone names ( _z_ ) cannot be parsed.**

So, what you can do is use a `gsub` filter to replace the timezone with a format recognized by logstash, like:

```
filter {
  grok { 
    match => {"message" => ["%{GREEDYDATA:date};%{USER:user};%{GREEDYDATA:webservice}"] } 
  }

  mutate {
    gsub => [
      "date", "CET", "+0100"
    ]
  }

  date {
    match => ["date", "EEE MMM dd HH:mm:ss Z yyyy"]
  }
}

```

This way `CET` will be replaced with `+0100`, it'll be recognized by logstash and correctly parsed by the capital `Z`.

Let me know if it works 🙂

---

<div class="post-metadata">

**Author:** ![dbviz](https://avatars.discourse-cdn.com/v4/letter/d/e19b73/32.png) [@dbviz](https://discuss.elastic.co/u/dbviz)\
**Post date:** [March 6, 2020, 3:30pm UTC](https://discuss.elastic.co/t/create-grok-filter-date/222285/4 "2020-03-06T15:30:05Z")

</div>

@Fabio-sama Thank you ! I fixed the issue with gsub, good idea. 👍

---

<div class="post-metadata">

**Author:** ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)\
**Post date:** [March 6, 2020, 3:46pm UTC](https://discuss.elastic.co/t/create-grok-filter-date/222285/5 "2020-03-06T15:46:17Z")

</div>

No problem 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2020, 3:46pm UTC](https://discuss.elastic.co/t/create-grok-filter-date/222285/6 "2020-04-03T15:46:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
