Date Field Issue in kibana filtering

Hi,

In kibana, when I tried to filter the date field, it is not filtering and showing the error message. PFB the error.
Error: Request to Elasticsearch failed: {"error":{"root_cause":[{"type":"parse_exception","reason":"failed to parse date field [2020-01-28T09:35:02.000Z] with format [yyyy-MM-dd HH:mm:ss||yyyy-MM-dd'T'HH:mm:ss.SSSZ||yyyy-MM-dd'T'HH:mm:ss||yyyy-MM-dd'T'HH:mm:ss.SSS||yyyy-MM-dd'T'HH:mm:ss.SSS||yyyy-MM-dd'T'HH:mm:ss.SSSZZ]: [failed to parse date field [2020-01-28T09:35:02.000Z] with format [yyyy-MM-dd HH:mm:ss||yyyy-MM-dd'T'HH:mm:ss.SSSZ||yyyy-MM-dd'T'HH:mm:ss||yyyy-MM-dd'T'HH:mm:ss.SSS||yyyy-MM-dd'T'HH:mm:ss.SSS||yyyy-MM-dd'T'HH:mm:ss.SSSZZ]]"}],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"query","grouped":true,"failed_shards":[{"shard":0,"index":"jobfailure","node":"n7biTiqiQKmdzXI2zb3-5A","reason":{"type":"query_shard_exception","reason":"failed to create query: {\n "bool" : {\n "filter" : [\n {\n "match_all" : {\n "boost" : 1.0\n }\n },\n {\n "match_phrase" : {\n "end" : {\n "query" : "2020-01-28T09:35:02.000Z",\n "slop" : 0,\n "zero_terms_query" : "NONE",\n "boost" : 1.0\n }\n }\n }\n ],\n "adjust_pure_negative" : true,\n "boost" : 1.0\n }\n}","index_uuid":"lXjVYczAQ2G717bCt7aE3Q","index":"jobfailure","caused_by":{"type":"parse_exception","reason":"failed to parse date field [2020-01-28T09:35:02.000Z] with format [yyyy-MM-dd HH:mm:ss||yyyy-MM-dd'T'HH:mm:ss.SSSZ||yyyy-MM-dd'T'HH:mm:ss||yyyy-MM-dd'T'HH:mm:ss.SSS||yyyy-MM-dd'T'HH:mm:ss.SSS||yyyy-MM-dd'T'HH:mm:ss.SSSZZ]: [failed to parse date field [2020-01-28T09:35:02.000Z] with format [yyyy-MM-dd HH:mm:ss||yyyy-MM-dd'T'HH:mm:ss.SSSZ||yyyy-MM-dd'T'HH:mm:ss||yyyy-MM-dd'T'HH:mm:ss.SSS||yyyy-MM-dd'T'HH:mm:ss.SSS||yyyy-MM-dd'T'HH:mm:ss.SSSZZ]]","caused_by":{"type":"illegal_argument_exception","reason":"failed to parse date field [2020-01-28T09:35:02.000Z] with format [yyyy-MM-dd HH:mm:ss||yyyy-MM-dd'T'HH:mm:ss.SSSZ||yyyy-MM-dd'T'HH:mm:ss||yyyy-MM-dd'T'HH:mm:ss.SSS||yyyy-MM-dd'T'HH:mm:ss.SSS||yyyy-MM-dd'T'HH:mm:ss.SSSZZ]","caused_by":{"type":"date_time_parse_exception","reason":"Failed to parse with all enclosed parsers"}}}}}],"caused_by":{"type":"parse_exception","reason":"failed to parse date field [2020-01-28T09:35:02.000Z] with format [yyyy-MM-dd HH:mm:ss||yyyy-MM-dd'T'HH:mm:ss.SSSZ||yyyy-MM-dd'T'HH:mm:ss||yyyy-MM-dd'T'HH:mm:ss.SSS||yyyy-MM-dd'T'HH:mm:ss.SSS||yyyy-MM-dd'T'HH:mm:ss.SSSZZ]: [failed to parse date field [2020-01-28T09:35:02.000Z] with format [yyyy-MM-dd HH:mm:ss||yyyy-MM-dd'T'HH:mm:ss.SSSZ||yyyy-MM-dd'T'HH:mm:ss||yyyy-MM-dd'T'HH:mm:ss.SSS||yyyy-MM-dd'T'HH:mm:ss.SSS||yyyy-MM-dd'T'HH:mm:ss.SSSZZ]]","caused_by":{"type":"illegal_argument_exception","reason":"failed to parse date field [2020-01-28T09:35:02.000Z] with format [yyyy-MM-dd HH:mm:ss||yyyy-MM-dd'T'HH:mm:ss.SSSZ||yyyy-MM-dd'T'HH:mm:ss||yyyy-MM-dd'T'HH:mm:ss.SSS||yyyy-MM-dd'T'HH:mm:ss.SSS||yyyy-MM-dd'T'HH:mm:ss.SSSZZ]","caused_by":{"type":"date_time_parse_exception","reason":"Failed to parse with all enclosed parsers"}}}},"status":400}
at http://localhost:5601/bundles/commons.bundle.js:3:4897411
at Function._module.service.Promise.try (http://localhost:5601/bundles/commons.bundle.js:3:2501410)
at http://localhost:5601/bundles/commons.bundle.js:3:2500784
at Array.map ()
at Function._module.service.Promise.map (http://localhost:5601/bundles/commons.bundle.js:3:2500741)
at callResponseHandlers (http://localhost:5601/bundles/commons.bundle.js:3:4895925)
at http://localhost:5601/bundles/commons.bundle.js:3:4878286
at processQueue (http://localhost:5601/built_assets/dlls/vendors.bundle.dll.js:435:204190)
at http://localhost:5601/built_assets/dlls/vendors.bundle.dll.js:435:205154
at Scope.$digest (http://localhost:5601/built_assets/dlls/vendors.bundle.dll.js:435:215159)

I matched the all the possible formats for my date field. But I don't know the error.
My date field data -- > 2020-01-30 06:00:00
My format ---> "format": "yyyy-MM-dd HH:mm:ss||yyyy-MM-dd'T'HH:mm:ss.SSSZ||yyyy-MM-dd'T'HH:mm:ss||yyyy-MM-dd'T'HH:mm:ss.SSS||yyyy-MM-dd'T'HH:mm:ss.SSS||yyyy-MM-dd'T'HH:mm:ss.SSSZZ"

Please help to solve this issue.

Regards,
Sangeetha Sivaji

Seems that those error messages are coming from ElasticSearch:

Can you please give more description of what you are doing in Kibana, possibly add screenshot? Which version of Kibana are you using?

Hi Vadims_Daleckis,
I am using kibana 7.3.1.
Yes, Error messages coming elasticsearch. I pushing the data to elasticsearch through api using dev tools in kibana. And I am creating the mappings in same dev tools.
As mentioned above, I will add images of my kibana.

while I'm trying to filter the date field those error messages are coming.
I tried to put all possible formats to match my date.
Though, same kind of error is coming.

I checked my mappings but I couldn't find any logical issues.
Please help me out.

Regards,
Sangeetha Sivaji

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.