# Date filter - how to parse separately grokked DATE and TIME

**URL:** <https://discuss.elastic.co/t/date-filter-how-to-parse-separately-grokked-date-and-time/202712>\
**Category:** Logstash\
**Created:** [October 8, 2019, 6:18pm UTC](https://discuss.elastic.co/t/date-filter-how-to-parse-separately-grokked-date-and-time/202712 "2019-10-08T18:18:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kmiklas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmiklas/32/50730_2.png) [@kmiklas](https://discuss.elastic.co/u/kmiklas)\
**Post date:** [October 8, 2019, 6:18pm UTC](https://discuss.elastic.co/t/date-filter-how-to-parse-separately-grokked-date-and-time/202712/1 "2019-10-08T18:18:54Z")

</div>

Hello All,

I have separately grokked DATE and TIME fields from a comma-separated string.

I now wish to filter them from two string into a date/time format with the Logstash `date` filter plugin.

I'm struggling with the syntax. I've tried the following. Where am I going wrong?

Thx, Keith :^)

- DATE groks successfully; format is `20191009`
- TIME groks successfully; format is `14:23:33`

~ does not work, but doesn't break.

```
date {
    match => ["[DATE][TIME]", "yyyymmddHH:mm:ss"]
        target => "@timestamp"
    }

```

~ error: Invalid FieldReference: `%{[DATE]}%{[TIME]}`

```
    date {
        match => ["%{[DATE]}%{[TIME]}", "yyyymmddHH:mm:ss"]
        target => "@timestamp"
    }

```

EDIT: I suppose really what I am asking is how to concatenate the date and time. Using the "+" char, it would be:

```
date {
    match => ["[DATE]+[TIME]", "yyyymmddHH:mm:ss"]
        target => "@timestamp"
    }
```

---

<div class="post-metadata">

**Author:** ![kmiklas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmiklas/32/50730_2.png) [@kmiklas](https://discuss.elastic.co/u/kmiklas)\
**Post date:** [October 10, 2019, 2:19pm UTC](https://discuss.elastic.co/t/date-filter-how-to-parse-separately-grokked-date-and-time/202712/2 "2019-10-10T14:19:23Z")

</div>

For posterity, I used Ruby:

```
    ruby {
        code => "
            d = event.get('[msg][DATE]')
            t = event.get('[msg][TIME]')
            dt = d + '_'
            if t.kind_of? Array
                dt = dt + t[0]
            else
                dt = dt + t
            end
            event.set('date_time', dt)
        "
    }

```

`date_time` was then fed into the Date filter.

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [October 10, 2019, 6:32pm UTC](https://discuss.elastic.co/t/date-filter-how-to-parse-separately-grokked-date-and-time/202712/3 "2019-10-10T18:32:11Z")

</div>

You could use a mutate filter to combine the fields into a single field, and then use the date filter targeting that field; in this case, I combined them into `[@metadata][combined_date]`, and since it is a subkey of `@metadata` it will not be included in the output so there is no need to clean it up.

```auto
filter {
  mutate {
    update => {
      "[@metadata][combined_date]" => "%{[msg][DATE]} %{[msg][TIME]}"
    }
  }
  date {
    match => ["[@metadata][combined_date]", "yyyymmdd HH:mm:ss"]
    target => "@timestamp"
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 7, 2019, 6:32pm UTC](https://discuss.elastic.co/t/date-filter-how-to-parse-separately-grokked-date-and-time/202712/4 "2019-11-07T18:32:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
