# Date field format in Logstash

**URL:** <https://discuss.elastic.co/t/date-field-format-in-logstash/50267>\
**Category:** Logstash\
**Created:** [May 17, 2016, 9:28pm UTC](https://discuss.elastic.co/t/date-field-format-in-logstash/50267 "2016-05-17T21:28:15Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![aalaie](https://avatars.discourse-cdn.com/v4/letter/a/9e8a1a/32.png) [@aalaie](https://discuss.elastic.co/u/aalaie)\
**Post date:** [May 17, 2016, 9:28pm UTC](https://discuss.elastic.co/t/date-field-format-in-logstash/50267/1 "2016-05-17T21:28:15Z")

</div>

Hi, I am new to ELK; I am trying to get my first example working but Logstash doesn't seem to like my **date** format.

stock.conf

input {  
file {  
path =\> ["/Users/alialaie/Desktop/Examples/Data/Intro/stock.csv"]  
start\_position =\> "beginning"  
sincedb\_path =\> "/dev/null"  
}  
}  
filter {  
csv {  
separator =\> ","  
columns =\> ["Date","Open","High","Low","Close","Volume","Adj Close"]  
}

```
  date {
        match => ["Date", "dd-MM-yyyy HH:mm:ss"]
    }

```

mutate {convert =\> ["High", "float"]}  
mutate {convert =\> ["Open", "float"]}  
mutate {convert =\> ["Low", "float"]}  
mutate {convert =\> ["Close", "float"]}  
mutate {convert =\> ["Volume", "float"]}  
mutate {convert =\> ["Adj Close", "float"]}

}

output {  
elasticsearch {  
hosts =\> "[http://localhost:9200](http://localhost:9200)"  
action =\> "index"  
index =\> "stock"}  
}

Here is the sample of **stock.csv**

Date,Open,High,Low,Close,Volume,Adj Close^M  
02-04-2015 12:01:01,125.029999,125.559998,124.190002,125.32,32220100,122.294596^M  
01-04-2015 12:01:01,124.82,125.120003,123.099998,124.25,40621400,121.250427^M  
31-03-2015 12:01:01,126.089996,126.489998,124.360001,124.43,42090600,121.426082^M  
30-03-2015 12:01:01,124.050003,126.400002,124,126.370003,47099700,123.31925^M  
27-03-2015 12:01:01,124.57,124.699997,122.910004,123.25,39546200,120.274569^M  
26-03-2015 12:01:01,122.760002,124.879997,122.599998,124.239998,47572900,121.240667^M  
25-03-2015 12:01:01,126.540001,126.82,123.379997,123.379997,51655200,120.401428^M  
24-03-2015 12:01:01,127.230003,128.039993,126.559998,126.690002,32842300,123.631525^M  
23-03-2015 12:01:01,127.120003,127.849998,126.519997,127.209999,37709700,124.138968^M

Any help would be appreciated.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 18, 2016, 6:13am UTC](https://discuss.elastic.co/t/date-field-format-in-logstash/50267/2 "2016-05-18T06:13:07Z")

</div>

The date filter works fine for me.

```auto
$ cat test.config 
input { stdin {} }
output { stdout { codec => rubydebug } }
filter {
  date {
    match => ["message", "dd-MM-yyyy HH:mm:ss"]
  }
}
$ echo '02-04-2015 12:01:01' | /opt/logstash/bin/logstash -f test.config
Settings: Default pipeline workers: 8
Logstash startup completed
{
       "message" => "02-04-2015 12:01:01",
      "@version" => "1",
    "@timestamp" => "2015-04-02T10:01:01.000Z",
          "host" => "lnxolofon"
}
Logstash shutdown completed

```

What do your events look like? Use a `stdout { codec => rubydebug }` output while debugging.

---

<div class="post-metadata">

**Author:** ![aalaie](https://avatars.discourse-cdn.com/v4/letter/a/9e8a1a/32.png) [@aalaie](https://discuss.elastic.co/u/aalaie)\
**Post date:** [May 18, 2016, 7:13pm UTC](https://discuss.elastic.co/t/date-field-format-in-logstash/50267/3 "2016-05-18T19:13:31Z")

</div>

Hi Magus;  
Did my homework. On the test.config the output looks like this :  
Pipeline main started  
{  
"message" =\> "02-04-2015 12:01:01",  
"@version" =\> "1",  
"@timestamp" =\> "2015-04-02T10:01:01.000Z",  
"host" =\> "Alis-MBP.home"  
}  
Pipeline main has been shutdown

The outcome of the stdout {codec=\> rubydebug } looks like this  
{  
"message" =\> "16-12-1980 12:01:01,25.375,25.375,25.25,25.25,26432000,0.378845\r",  
"@version" =\> "1",  
"@timestamp" =\> "1980-12-16T11:01:01.000Z",  
"path" =\> "/Users/alialaie/Desktop/Examples/Data/Intro/stock.csv",  
"host" =\> "Alis-MBP.home",  
"Date" =\> "16-12-1980 12:01:01",  
"Open" =\> 25.375,  
"High" =\> 25.375,  
"Low" =\> 25.25,  
"Close" =\> 25.25,  
"Volume" =\> 26432000.0,  
"Adj Close" =\> 0.378845  
}  
Date is being picked by ES as string and not a date. Am I doing something wrong here.  
Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 18, 2016, 8:36pm UTC](https://discuss.elastic.co/t/date-field-format-in-logstash/50267/4 "2016-05-18T20:36:23Z")

</div>

The `@timestamp` field is populated from the `message` field exactly as expected (assuming your timezone is UTC+1), so we're good there. But you're saying the field in Elasticsearch has the wrong mapping? Did you determine that with the get mapping API?

---

<div class="post-metadata">

**Author:** ![aalaie](https://avatars.discourse-cdn.com/v4/letter/a/9e8a1a/32.png) [@aalaie](https://discuss.elastic.co/u/aalaie)\
**Post date:** [May 18, 2016, 10:47pm UTC](https://discuss.elastic.co/t/date-field-format-in-logstash/50267/5 "2016-05-18T22:47:00Z")

</div>

This is what I did just right now:  
curl -XGET '[http://localhost:9200/stock](http://localhost:9200/stock)'  
{"stock":{"aliases":{},"mappings":{"logs":{"properties":{"@timestamp":{"type":"date","format":" **strict\_date\_optional\_time||epoch\_millis**"},"

When I go to kibana to find my index, the field "Date" of type "date" is not being recognised as time field event. The only time field event is @timestamp. Am I doing something wrong here.  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/6/69896917e166d6a45ed92c0b294f419da1a3616f.jpg)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 19, 2016, 5:35am UTC](https://discuss.elastic.co/t/date-field-format-in-logstash/50267/6 "2016-05-19T05:35:24Z")

</div>

Well, if you want the date filter to write to the `Date` field instead of `@timestamp` you'll have to configure it accordingly (using the `target` option). Secondly you'll want to explicitly map the `Date` field as the date type, preferably using an index template.

---

<div class="post-metadata">

**Author:** ![aalaie](https://avatars.discourse-cdn.com/v4/letter/a/9e8a1a/32.png) [@aalaie](https://discuss.elastic.co/u/aalaie)\
**Post date:** [May 22, 2016, 7:27pm UTC](https://discuss.elastic.co/t/date-field-format-in-logstash/50267/7 "2016-05-22T19:27:37Z")

</div>

Thanks. Problem solved.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:56am UTC](https://discuss.elastic.co/t/date-field-format-in-logstash/50267/8 "2017-07-06T04:56:44Z")

</div>


