# Date Field in in Logstash

**URL:** <https://discuss.elastic.co/t/date-field-in-in-logstash/167963>\
**Category:** Logstash\
**Created:** [February 12, 2019, 6:25am UTC](https://discuss.elastic.co/t/date-field-in-in-logstash/167963 "2019-02-12T06:25:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alok](https://avatars.discourse-cdn.com/v4/letter/a/a8b319/32.png) [@Alok](https://discuss.elastic.co/u/Alok)\
**Post date:** [February 12, 2019, 6:25am UTC](https://discuss.elastic.co/t/date-field-in-in-logstash/167963/1 "2019-02-12T06:25:14Z")

</div>

I have some date fields in CSV which I would like to have as Type Date in the Index.  
When the index is created the type remains 'text' despite many ways of handling it.

The config file looks like as under :

```auto
input {
  file {
    path => "D:\test.csv"
    start_position => "beginning"
   sincedb_path => "/dev/null"
  }
}
filter {
  csv {
      separator => ","
     columns => 
    ["A","B","C","Date_field1","date_field2"] 
  }

     mutate{
        convert => {
        "B" => "integer"
          }
        }
  date {
match => ["Date_field1", "dd-MM-yyyy HH:mm:ss.SSS"]
target => "Date_field1"
}		
    }
output {
   elasticsearch {
     hosts => "localhost:9200"
     index => "test"
  }
stdout {codec=>rubydebug}

```

I am getting errors in logstash like "\_dateparsefailure"

The index is created with Date\_field1 being type text

Please help.

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [February 12, 2019, 6:49am UTC](https://discuss.elastic.co/t/date-field-in-in-logstash/167963/2 "2019-02-12T06:49:31Z")

</div>

First, what are some example date strings in your CSV? The `_dateparsefailure` tag indicates that none of the provided patterns matched, so it was unable to parse the string. The format specification for the `match` directive is described in detail in the [Logstash Date Filter Plugin docs](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html#plugins-filters-date-match).

* * *

Second, you may want to configure your Elasticsearch output to manage your index templates for you using the [`template` directive](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-template). Doing so will ensure that _new_ indices handle fields in the way you expect (installing a template will _not_ affect the mappings of existing indices).

When Elasticsearch receives a document for an index that has not yet been created, it looks through the registered templates for one or more whose pattern matches the index name. These templates define the mappings of fields to their types. When an Elasticsearch index receives a document that contains a field that is not yet defined on the index, it makes a "best guess" as to the type of the field. Subsequent documents will be coerced to that type.

What that means, is if the `Date_field1` field has already been created as a text field in your index, no matter if you change it to a date in Logstash, when the document is inserted into Elasticsearch, since the index's existing type for the field is text, it will coerce the given value into text value.

---

<div class="post-metadata">

**Author:** ![Alok](https://avatars.discourse-cdn.com/v4/letter/a/a8b319/32.png) [@Alok](https://discuss.elastic.co/u/Alok)\
**Post date:** [February 12, 2019, 6:54am UTC](https://discuss.elastic.co/t/date-field-in-in-logstash/167963/3 "2019-02-12T06:54:24Z")

</div>

Thanks. Will try via template way

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 12, 2019, 6:54am UTC](https://discuss.elastic.co/t/date-field-in-in-logstash/167963/4 "2019-03-12T06:54:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
