# Date filter configuration error

**URL:** https://discuss.elastic.co/t/date-filter-configuration-error/46147
**Category:** Logstash
**Created:** [April 3, 2016, 2:46am UTC](https://discuss.elastic.co/t/date-filter-configuration-error/46147 "2016-04-03T02:46:22Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![manishr](https://avatars.discourse-cdn.com/v4/letter/m/c57346/32.png) [@manishr](https://discuss.elastic.co/u/manishr)
#### Post date: [April 3, 2016, 2:46am UTC](https://discuss.elastic.co/t/date-filter-configuration-error/46147/1 "2016-04-03T02:46:22Z")

</div>

HI Guys,

I am trying to replace @timestamp with tstamp but it is not working. What am I missing here? Here is my configuration

```
     date {
            match => ["tstamp","yyyy-MM-dd'T'HH:mm:ss.SSSZ"]
            target => "@timestamp"
    }

```

and the sample date entry is like this

2016-04-02T09:29:50.348Z  
2016-04-02T08:52:49Z  
2016-04-02T02:52:50.000Z

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [April 4, 2016, 5:40am UTC](https://discuss.elastic.co/t/date-filter-configuration-error/46147/2 "2016-04-04T05:40:22Z")

</div>

You should be able to use the special ISO8601 pattern. The problem with your current pattern might be that the "Z" Joda-Time pattern can't parse the "Z" in the string. If the timezone is always "Z" you should be able to treat it like a literal and single-quote the "Z" in the pattern.

---

<div class="post-metadata">

### Author: ![manishr](https://avatars.discourse-cdn.com/v4/letter/m/c57346/32.png) [@manishr](https://discuss.elastic.co/u/manishr)
#### Post date: [April 4, 2016, 6:08am UTC](https://discuss.elastic.co/t/date-filter-configuration-error/46147/3 "2016-04-04T06:08:36Z")

</div>

Thanks @magnusbaeck, it is working fine. But what if I want to replace timestamp with a array field. Will it work like this

date {  
match =\> ["[a].[b]","ISO8601"]  
target =\> "@timestamp"  
}

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [April 4, 2016, 6:14am UTC](https://discuss.elastic.co/t/date-filter-configuration-error/46147/4 "2016-04-04T06:14:05Z")

</div>

See [https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references) for the syntax for nested fields.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 5:04am UTC](https://discuss.elastic.co/t/date-filter-configuration-error/46147/5 "2017-07-06T05:04:10Z")

</div>


