# Date filter issues

**URL:** <https://discuss.elastic.co/t/date-filter-issues/35455>\
**Category:** Logstash\
**Created:** [November 24, 2015, 1:45pm UTC](https://discuss.elastic.co/t/date-filter-issues/35455 "2015-11-24T13:45:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kryten](https://avatars.discourse-cdn.com/v4/letter/k/58956e/32.png) [@Kryten](https://discuss.elastic.co/u/Kryten)\
**Post date:** [November 24, 2015, 1:45pm UTC](https://discuss.elastic.co/t/date-filter-issues/35455/1 "2015-11-24T13:45:36Z")

</div>

Having problems updating the @timestamp value for my messages. Would appreciate any insight into what might be going wrong here.

Sample log line:-  
`2015-11-24 11:44:55,888 INFO [com.blandio.ct.avd.dao.CSDAO: 238] - Disconnect received.`

My date filter looks like:  
filter {

```
		grok {
			match	=> ["message","(?<tstamp>\d{4}\-\d{2}\-\d{2}\s\d{2}\:\d{2}\:\d{2}\,\d{3})"]
		}
		date {
			match => ["%{tstamp}","yyyy-MM-dd HH:mm:ss,SSS"]
		}
}

```

so in this case I am capturing the timestamp with a grok and then using the field the grok creates as the value for date to match against. This fails as tthe @timestamp value is just the logstash parse time not the log event time.

I have tried without the initial grok - just the same. I have tried using lowercase "mm" for the month - just the same.  
I have tried using locale and target parameters to update an existing field - just the same.

Would appreciate any help as to why this is failing.

Many thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 24, 2015, 1:46pm UTC](https://discuss.elastic.co/t/date-filter-issues/35455/2 "2015-11-24T13:46:59Z")

</div>

> ```
> match => ["%{tstamp}","yyyy-MM-dd HH:mm:ss,SSS"]
> 
> ```

Correct:

```
match => ["tstamp","yyyy-MM-dd HH:mm:ss,SSS"]

```

---

<div class="post-metadata">

**Author:** ![Kryten](https://avatars.discourse-cdn.com/v4/letter/k/58956e/32.png) [@Kryten](https://discuss.elastic.co/u/Kryten)\
**Post date:** [November 24, 2015, 1:49pm UTC](https://discuss.elastic.co/t/date-filter-issues/35455/3 "2015-11-24T13:49:59Z")

</div>

Awesome!  
Yep that did it. Interestingly, without the grok I get a [dateparsefailure] tag.. I thought that grokking out a nice clean value would help... trust me to not reference it properly though!  
Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:21am UTC](https://discuss.elastic.co/t/date-filter-issues/35455/4 "2017-07-06T05:21:29Z")

</div>


