# Date Field as "Date" Time as "Time" - Why this so hard to do in Logstash?

**URL:** <https://discuss.elastic.co/t/date-field-as-date-time-as-time-why-this-so-hard-to-do-in-logstash/164487>\
**Category:** Logstash\
**Created:** [January 16, 2019, 3:07pm UTC](https://discuss.elastic.co/t/date-field-as-date-time-as-time-why-this-so-hard-to-do-in-logstash/164487 "2019-01-16T15:07:55Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Datakids](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/datakids/32/39622_2.png) [@Datakids](https://discuss.elastic.co/u/Datakids)\
**Post date:** [January 16, 2019, 3:07pm UTC](https://discuss.elastic.co/t/date-field-as-date-time-as-time-why-this-so-hard-to-do-in-logstash/164487/1 "2019-01-16T15:07:56Z")

</div>

Hi all,

I mess arround with my csv and a date field formatted as "DD.MM.YYYY"

![grafik](https://us1.discourse-cdn.com/elastic/original/3X/1/d/1ddec982696c18b5c0845d3369b78fa963df13a5.png)

But whatever I do Logstash Filter will ignore all --\> still "String"  
Even the data\_formatted plug in will not work as I expected.

What I want is this: but instead of @timestamp as Date I want the csv Date as "Date" --\> but no way and I have no ideas left!

![grafik](https://us1.discourse-cdn.com/elastic/original/3X/d/c/dcaab33c44a30dabe90f9bd38c62eb9da98169b7.png)

Why the ELK Stack have so many problems / troubles by managing the most obvious informations like Date and Time?  
Why this so hard to do the date {} Filter in Logstash?  
This must be a simple task, but it's not!

Please what can I do to manage this?  
Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 16, 2019, 3:33pm UTC](https://discuss.elastic.co/t/date-field-as-date-time-as-time-why-this-so-hard-to-do-in-logstash/164487/2 "2019-01-16T15:33:33Z")

</div>

If you try

```
date { match => ["Date", "dd.MM.YYYY"] target => "Date" }

```

what issues do you have with the result?

---

<div class="post-metadata">

**Author:** ![Datakids](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/datakids/32/39622_2.png) [@Datakids](https://discuss.elastic.co/u/Datakids)\
**Post date:** [January 16, 2019, 4:01pm UTC](https://discuss.elastic.co/t/date-field-as-date-time-as-time-why-this-so-hard-to-do-in-logstash/164487/3 "2019-01-16T16:01:23Z")

</div>

Hi,  
thanks for reply!  
I tried, result is:

 ![grafik](https://us1.discourse-cdn.com/elastic/original/3X/f/d/fd2f62dfa228b34e1779687dc3be6a92879595f6.png)

Any suggestions ?

Note, following Syntax is not working in my conf file:

> date {  
> match =\> ["Date", "dd.MM.YYYY"]  
> target =\> "Date"  
> }

That is what I tried before, hm hm, maybe quiet sensitiv somewhere between the spaces...

Regards

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 16, 2019, 4:13pm UTC](https://discuss.elastic.co/t/date-field-as-date-time-as-time-why-this-so-hard-to-do-in-logstash/164487/4 "2019-01-16T16:13:10Z")

</div>

> [@Datakids](#):
>
> following Syntax is not working in my conf file

In what way does it not work?

Note that once a mapping is established in elasticsearch, such as Date being a string, it cannot be changed without creating a new index. So when you are debugging things like this you need to keep deleting the index as you try each iteration in logstash.

---

<div class="post-metadata">

**Author:** ![Datakids](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/datakids/32/39622_2.png) [@Datakids](https://discuss.elastic.co/u/Datakids)\
**Post date:** [January 16, 2019, 4:34pm UTC](https://discuss.elastic.co/t/date-field-as-date-time-as-time-why-this-so-hard-to-do-in-logstash/164487/5 "2019-01-16T16:34:44Z")

</div>

Thats what I did before try yours!  
Clean all ES and Filebeat

The field Date still mapped as a String.  
Believe me, I'm getting frustraded and I dont know why the hell this is not working.  
I tried everything I found here in this discuss forum even the plugin date\_formatted which will give  
access to change the pattern of a field.  
Nothing works.  
My wish: An Optional "Auto-Type" for fields they look like what they probably are no matter from what format  
"Date is Date" "Time is Time" "Number is Number" etc.

---

<div class="post-metadata">

**Author:** ![Datakids](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/datakids/32/39622_2.png) [@Datakids](https://discuss.elastic.co/u/Datakids)\
**Post date:** [January 16, 2019, 4:44pm UTC](https://discuss.elastic.co/t/date-field-as-date-time-as-time-why-this-so-hard-to-do-in-logstash/164487/6 "2019-01-16T16:44:01Z")

</div>

Here is the interesting part

csv {  
columns =\>["Date","Time","Year","Month","Day"]  
separator =\> "|"  
quote\_char =\> "~"  
}  
mutate {split =\> { "message" =\> "|" }}  
mutate {add\_field =\> {"Date" =\> "%{[message][0]}"}}  
mutate {add\_field =\> {"Time" =\> "%{[message][1]}"}}  
mutate {add\_field =\> {"Year" =\> "%{[message][2]}"}}  
mutate {add\_field =\> {"Month" =\> "%{[message][3]}"}}  
mutate {add\_field =\> {"Day" =\> "%{[message][4]}"}}  
mutate {convert =\> ["Year","integer"]}  
mutate {convert =\> ["Day","integer"]}   
date {  
match =\> ["Date", "dd.MM.YYYY"]  
target =\> "Date"  
}

logstash convert everything, all good but Date! Even with your advice!?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 16, 2019, 5:03pm UTC](https://discuss.elastic.co/t/date-field-as-date-time-as-time-why-this-so-hard-to-do-in-logstash/164487/7 "2019-01-16T17:03:06Z")

</div>

Change the target to a new name

```
target => "DateABCD"

```

Ingest some documents, do the index pattern refresh in Kibana and see what you get for that field.

---

<div class="post-metadata">

**Author:** ![Datakids](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/datakids/32/39622_2.png) [@Datakids](https://discuss.elastic.co/u/Datakids)\
**Post date:** [January 17, 2019, 10:36am UTC](https://discuss.elastic.co/t/date-field-as-date-time-as-time-why-this-so-hard-to-do-in-logstash/164487/8 "2019-01-17T10:36:01Z")

</div>

No Sir,

even the field DataABCD is missing !!!

 ![grafik](https://us1.discourse-cdn.com/elastic/original/3X/0/1/01acc16d2ac51440e72d1eb5f24ad2fbcebf7a06.png)

Any suggestions?

---

<div class="post-metadata">

**Author:** ![Datakids](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/datakids/32/39622_2.png) [@Datakids](https://discuss.elastic.co/u/Datakids)\
**Post date:** [January 17, 2019, 11:54am UTC](https://discuss.elastic.co/t/date-field-as-date-time-as-time-why-this-so-hard-to-do-in-logstash/164487/9 "2019-01-17T11:54:02Z")

</div>

Finaly Made it!  
I got some syntax errors while my added fields.  
Your advice works well 🙂  
However I hope there will be an AutoType for Fields in future updates.  
That will do things easier when working with bunch of different files.

Thanks Regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2019, 11:54am UTC](https://discuss.elastic.co/t/date-field-as-date-time-as-time-why-this-so-hard-to-do-in-logstash/164487/10 "2019-02-14T11:54:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
