# CSV Date Filter not working

**URL:** <https://discuss.elastic.co/t/csv-date-filter-not-working/161218>\
**Category:** Logstash\
**Created:** [December 17, 2018, 10:15pm UTC](https://discuss.elastic.co/t/csv-date-filter-not-working/161218 "2018-12-17T22:15:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kb2295](https://avatars.discourse-cdn.com/v4/letter/k/4491bb/32.png) [@kb2295](https://discuss.elastic.co/u/kb2295)\
**Post date:** [December 17, 2018, 10:15pm UTC](https://discuss.elastic.co/t/csv-date-filter-not-working/161218/1 "2018-12-17T22:15:59Z")

</div>

Hello. I have a CSV file that looks a bit like this:

> Date,Year,Month,Client,Execution Account,Source,SharedBook,I/E/H,FirmId,TraderLogin,Trader,Region,City,Exchange,ProductName,AssetClass,CTM,P&L,CFOXType,TradeType,HandleInst,Manual Fill,Strategy,HFT,Gratis,Sales Region,Legal Entity Region,Lots,OrderCount,FillCount,PerOfLots,PerOfOrders,PerOfFills,exchTraderId,execBrokerCode,tradingPlatform,responsiblePerson  
> "2017-09-20 00:00:00.0","2017","9","XXXX","TTTTT","ABC","FGH","E","XYZ","XYZ","XYZ","XYZ","XYZ","XYZ","XYZ-","ABs","GHI-00000","GHI","H","GHI","GHI","false","GHI","false","false","GHI","GHI","10","1","1","0","0","0","GH5555I","SSB","QQQ","PO0090"

I'm trying to use a .config file to upload the data. The "Date" field keeps showing up as a strign with the following configurations.

> input {  
> file {  
> path =\> "/tmp/path/fakeMIScsv.csv"  
> start\_position =\> "beginning"  
> sincedb\_path =\>"dev/null"  
> }
> 
> }  
> filter {  
> csv {  
> separator =\> ","  
> columns =\> ["Date","Year","Month","Client","Execution Account","Source","SharedBook","I\_E\_H","FirmId","TraderLogin","Trader","Region","City","Exchange","ProductName","AssetClass","CTM","P\_L","CFOXType","TradeType","HandleInst","Manual Fill","Strategy","HFT","Gratis","Sales Region","Legal Entity Region","Lots","OrderCount","FillCount","PerOfLots","PerOfOrders","PerOfFills","exchTraderId","execBrokerCode","tradingPlatform","responsiblePerson"]  
> }  
> mutate{  
> convert =\> {  
> "Lots" =\> "integer"  
> "OrderCount" =\> "integer"  
> "FillCount" =\> "integer"  
> "PerOfLots" =\> "integer"  
> "PerOfOrders" =\> "integer"  
> "PerOfFills" =\> "integer"  
> }  
> }  
> date {  
> target =\> "Date"  
> match =\> ["Date", "yyyy-MM-dd HH:mm:ss"]  
> }  
> }
> 
> output {  
> elasticsearch {  
> hosts=\> ["abc","xyz","abcd"]  
> index =\> "delete4"  
> user =\> \*\*\*\*\*  
> password =\> \*\*\*\*\*  
> ssl =\> true  
> ssl\_certificate\_verification =\> false  
> cacert =\> '/path/to/cert/ca.crt'  
> }  
> stdout {}  
> }

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [December 18, 2018, 12:47am UTC](https://discuss.elastic.co/t/csv-date-filter-not-working/161218/2 "2018-12-18T00:47:52Z")

</div>

Are the events also being tagged with `_dateparsefailure`?

I think I found the problem. The format string you have specified in your Date filter does not match the exact format of the value of the fields; the example you posted included sub-second precision, but the format string you provide doesn't.

```auto
date {
  target => "Date"
  match =>; ["Date", "yyyy-MM-dd HH:mm:ss.S"]
}

```

For more info on the acceptible date format strings, check out [the docs](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html#plugins-filters-date-match).

---

<div class="post-metadata">

**Author:** ![kb2295](https://avatars.discourse-cdn.com/v4/letter/k/4491bb/32.png) [@kb2295](https://discuss.elastic.co/u/kb2295)\
**Post date:** [December 18, 2018, 9:45pm UTC](https://discuss.elastic.co/t/csv-date-filter-not-working/161218/3 "2018-12-18T21:45:35Z")

</div>

This fixed it. Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2019, 9:45pm UTC](https://discuss.elastic.co/t/csv-date-filter-not-working/161218/4 "2019-01-15T21:45:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
