# Date filter dosen't work

**URL:** <https://discuss.elastic.co/t/date-filter-dosent-work/121870>\
**Category:** Logstash\
**Created:** [February 28, 2018, 2:28pm UTC](https://discuss.elastic.co/t/date-filter-dosent-work/121870 "2018-02-28T14:28:05Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![akml\_kk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akml_kk/32/31069_2.png) [@akml\_kk](https://discuss.elastic.co/u/akml_kk)\
**Post date:** [February 28, 2018, 2:28pm UTC](https://discuss.elastic.co/t/date-filter-dosent-work/121870/1 "2018-02-28T14:28:05Z")

</div>

hello why my date filter dosen't work, i've seen a lot of question here and they helped me to optimise my configuration, but date filter still dosen't work :

my column1 still of type String and i still got a @timestamp seapratly with today is time

```
 input{ 

file{

path => "C:\Users\GeeksData\Desktop\ElasticSerach\tablelogg.csv"
start_position => "beginning"
sincedb_path =>NUL

}
}

filter{

csv{
	separator => ";"
	columns => ["column1","column2","column3","column4","column5"]

	}

  date {

		match => ["column1","dd/MM/yyyy HH:mm"]
		target => "@timestamp"
		 }

mutate{convert => ["column2","integer"]}

}

output{

elasticsearch{ 
hosts => "localhost"
index => "indice6"
document_type => "donnèes"

}
stdout { codec => rubydebug }

}
```

---

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [February 28, 2018, 2:35pm UTC](https://discuss.elastic.co/t/date-filter-dosent-work/121870/2 "2018-02-28T14:35:06Z")

</div>

what does your rubydebug output look like?  
In my configuration it looks like this (but I have other time format)

```
	date 
	{
		id => "ulog:date:logTime"
		match => ['logTime', 'YYYY-MM-dd HH:mm:ss']
		timezone => "Europe/Berlin"
		#remove_field => ['logTime']
	}
```

---

<div class="post-metadata">

**Author:** ![akml\_kk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akml_kk/32/31069_2.png) [@akml\_kk](https://discuss.elastic.co/u/akml_kk)\
**Post date:** [February 28, 2018, 2:39pm UTC](https://discuss.elastic.co/t/date-filter-dosent-work/121870/3 "2018-02-28T14:39:05Z")

</div>

This is what the console show i m using windows i can't copy it all  
"column1" =\> "12/07/2017 16:02",  
"@timestamp =\>"2017-07-12T14:02:000Z",  
........

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 28, 2018, 2:54pm UTC](https://discuss.elastic.co/t/date-filter-dosent-work/121870/4 "2018-02-28T14:54:45Z")

</div>

> This is what the console show i m using windows i can't copy it all  
> "column1" =\> "12/07/2017 16:02",  
> "@timestamp =\>"2017-07-12T14:02:000Z",  
> ........

That looks correct.

---

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [February 28, 2018, 3:03pm UTC](https://discuss.elastic.co/t/date-filter-dosent-work/121870/5 "2018-02-28T15:03:04Z")

</div>

@timestamp is shown / stored in utc.  
you should set your timezone explicitly.

---

<div class="post-metadata">

**Author:** ![akml\_kk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akml_kk/32/31069_2.png) [@akml\_kk](https://discuss.elastic.co/u/akml_kk)\
**Post date:** [February 28, 2018, 4:34pm UTC](https://discuss.elastic.co/t/date-filter-dosent-work/121870/6 "2018-02-28T16:34:45Z")

</div>

what i want is the columne1 ("which represent the time in my case"), convert from string to date.  
I'have read some posts here , may be i didn't understood them well, mentioning that i should create a date filter then add a target to timestamp so the timestamp would be the time of column1.

---

<div class="post-metadata">

**Author:** ![akml\_kk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akml_kk/32/31069_2.png) [@akml\_kk](https://discuss.elastic.co/u/akml_kk)\
**Post date:** [February 28, 2018, 4:35pm UTC](https://discuss.elastic.co/t/date-filter-dosent-work/121870/7 "2018-02-28T16:35:49Z")

</div>

Why timezone, what i want is the column1 being seen as a date instead of string thats all.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 28, 2018, 6:41pm UTC](https://discuss.elastic.co/t/date-filter-dosent-work/121870/8 "2018-02-28T18:41:43Z")

</div>

> what i want is the columne1 ("which represent the time in my case"), convert from string to date.

You can use the date filter to parse the original date and store it back to the same field (use the `target`) option. Then ES will auto-detect that field as a timestamp, but that will only happen when you recreate the index since the mapping of an index's field can't be changed.

You can also set the mapping explicitly to have ES accept the original field value as a timestamp.

---

<div class="post-metadata">

**Author:** ![akml\_kk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akml_kk/32/31069_2.png) [@akml\_kk](https://discuss.elastic.co/u/akml_kk)\
**Post date:** [February 28, 2018, 8:07pm UTC](https://discuss.elastic.co/t/date-filter-dosent-work/121870/9 "2018-02-28T20:07:33Z")

</div>

store it back to the same field , you mean like this :

```
date{
      match => ["column1","dd/MM/yyyy HH:mm"]
	target => "column1"

     }

```

?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 28, 2018, 8:37pm UTC](https://discuss.elastic.co/t/date-filter-dosent-work/121870/10 "2018-02-28T20:37:00Z")

</div>

Yes.

---

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [March 1, 2018, 7:48am UTC](https://discuss.elastic.co/t/date-filter-dosent-work/121870/11 "2018-03-01T07:48:08Z")

</div>

> [@akml\_kk](#):
>
> Why timezone

timezones are important, especially if you have logs where the dates are stored in different time zones.  
In our application, which we are monitoring with elastic stack, some logs have times stored in utc, other logs are using local time.

When I set the exact timezone for each log, then the date filter is converting correctly to utc.  
When querying a time interval in kibana, then all log entries / documents are shown correctly referring to my browsers timezone. So I don't need to remember which log is stored in which time zone as kibana user, because all documents are 'moved' to utc.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2018, 7:48am UTC](https://discuss.elastic.co/t/date-filter-dosent-work/121870/12 "2018-03-29T07:48:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
