# Date Filter Not working parsing IIS logs

**URL:** <https://discuss.elastic.co/t/date-filter-not-working-parsing-iis-logs/83071>\
**Category:** Logstash\
**Created:** [April 20, 2017, 2:18pm UTC](https://discuss.elastic.co/t/date-filter-not-working-parsing-iis-logs/83071 "2017-04-20T14:18:51Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Peter\_Dwyer](https://avatars.discourse-cdn.com/v4/letter/p/5f9b8f/32.png) [@Peter\_Dwyer](https://discuss.elastic.co/u/Peter_Dwyer)\
**Post date:** [April 20, 2017, 2:18pm UTC](https://discuss.elastic.co/t/date-filter-not-working-parsing-iis-logs/83071/1 "2017-04-20T14:18:51Z")

</div>

I'm having trouble with the date filter. it doesn't seem to be updating the timestamp correctly.

```
filter {
  if [type] == "iis" {
    grok {
      match => {"message" => "%{TIMESTAMP_ISO8601:log_timestamp} %{WORD:serviceName} %{IP:serverIP} %{WORD:method} %{URIPATH:uriStem} %{NOTSPACE:uriQuery} %{NUMBER:port} %{NOTSPACE:username} %{IPORHOST:clientIP} %{NOTSPACE:protocolVersion} %{NOTSPACE:userAgent} %{NOTSPACE:cookie} %{NOTSPACE:referer} %{NOTSPACE:requestHost} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:win32response} %{NUMBER:bytesSent} %{NUMBER:bytesReceived} %{NUMBER:timetaken}"}
    }
    date {
        match => ["log_timestamp", "YYYY-MM-dd HH:mm:ss", "ISO8601"]
        target => "@timestamp"
        remove_field => ["log_timestamp"]
    }
    mutate {
        convert => ["bytesSent", "integer"]
        convert => ["bytesReceived", "integer"]
        convert => ["timetaken", "integer"]
    }
    useragent {
        source=> "userAgent"
        prefix=> "browser."
        regexes=> "/etc/logstash/regexes.yaml"
    }

  }
}

```

This is the debug log. i have changed some details.

```
{
      "log_timestamp" => "2017-04-20 14:04:04",
            "referer" => "-",
      "win32response" => "0",
    "browser.os_name" => "Windows",
             "source" => "ex170420.log",
               "type" => "iis",
        "requestHost" => "hostname",
       "browser.name" => "Other",
          "timetaken" => 15,
         "browser.os" => "Windows",
           "clientIP" => "0.0.0.0",
           "@version" => "1",
               "beat" => {
        "hostname" => "HOST",
            "name" => "HOST",
         "version" => "5.3.0"
    },
               "host" => "HOST",
           "serverIP" => "0.0.0.0",
    "protocolVersion" => "HTTP/1.1",
             "offset" => 527048,
             "method" => "POST",
             "cookie" => "...",
            "uriStem" => "/",
         "input_type" => "log",
          "userAgent" => "Mozilla/4.0+...",
          "bytesSent" => 892,
            "message" => "2017-04-20 14:04:04 ...",
        "serviceName" => "W3SVC1",
               "tags" => [
        [0] "beats_input_codec_plain_applied",
        [1] "_dateparsefailure"
    ],
      "bytesReceived" => 908,
         "@timestamp" => 2017-04-20T14:05:08.919Z,
           "uriQuery" => "-",
               "port" => "80",
           "response" => "200",
        "subresponse" => "0",
             "fields" => {
        "log_type" => "W3SVC1"
    },
           "username" => "-",
     "browser.device" => "Other"
}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 20, 2017, 2:21pm UTC](https://discuss.elastic.co/t/date-filter-not-working-parsing-iis-logs/83071/2 "2017-04-20T14:21:41Z")

</div>

The Logstash log will contain details about what the date filter doesn't like with the string you want it to parse. Here I'm guessing you should use "YYYY-MM-dd HH:mm:ss" rather than "ISO8601".

---

<div class="post-metadata">

**Author:** ![Peter\_Dwyer](https://avatars.discourse-cdn.com/v4/letter/p/5f9b8f/32.png) [@Peter\_Dwyer](https://discuss.elastic.co/u/Peter_Dwyer)\
**Post date:** [April 20, 2017, 2:23pm UTC](https://discuss.elastic.co/t/date-filter-not-working-parsing-iis-logs/83071/3 "2017-04-20T14:23:48Z")

</div>

i was using that earlier and it didn't work either.  
i could configure it withthe below?  
match =\> ["log\_timestamp", "YYYY-MM-dd HH:mm:ss", "ISO8601"]

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 20, 2017, 2:24pm UTC](https://discuss.elastic.co/t/date-filter-not-working-parsing-iis-logs/83071/4 "2017-04-20T14:24:29Z")

</div>

Yes, the date filter supports multiple patterns.

---

<div class="post-metadata">

**Author:** ![Peter\_Dwyer](https://avatars.discourse-cdn.com/v4/letter/p/5f9b8f/32.png) [@Peter\_Dwyer](https://discuss.elastic.co/u/Peter_Dwyer)\
**Post date:** [April 20, 2017, 2:32pm UTC](https://discuss.elastic.co/t/date-filter-not-working-parsing-iis-logs/83071/5 "2017-04-20T14:32:39Z")

</div>

ok, i have updated the config in the question. now it is not parsing messages tagged with IIS.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 20, 2017, 2:34pm UTC](https://discuss.elastic.co/t/date-filter-not-working-parsing-iis-logs/83071/6 "2017-04-20T14:34:12Z")

</div>

As I said: The Logstash log will contain details about what the date filter doesn't like with the string you want it to parse.

---

<div class="post-metadata">

**Author:** ![Peter\_Dwyer](https://avatars.discourse-cdn.com/v4/letter/p/5f9b8f/32.png) [@Peter\_Dwyer](https://discuss.elastic.co/u/Peter_Dwyer)\
**Post date:** [April 20, 2017, 3:19pm UTC](https://discuss.elastic.co/t/date-filter-not-working-parsing-iis-logs/83071/7 "2017-04-20T15:19:36Z")

</div>

thanks that seems to have fixed it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2017, 3:21pm UTC](https://discuss.elastic.co/t/date-filter-not-working-parsing-iis-logs/83071/8 "2017-05-18T15:21:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
