# Date filter not working properly

**URL:** <https://discuss.elastic.co/t/date-filter-not-working-properly/96941>\
**Category:** Logstash\
**Created:** [August 14, 2017, 10:17am UTC](https://discuss.elastic.co/t/date-filter-not-working-properly/96941 "2017-08-14T10:17:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jonesthomas](https://avatars.discourse-cdn.com/v4/letter/j/f4b2a3/32.png) [@Jonesthomas](https://discuss.elastic.co/u/Jonesthomas)\
**Post date:** [August 14, 2017, 10:17am UTC](https://discuss.elastic.co/t/date-filter-not-working-properly/96941/1 "2017-08-14T10:17:17Z")

</div>

i have a string timestamp field in my log,i need to change the string to date format,  
This is my sample log file:  
{"LogMsg":"{"type":"GAUGE", "name":"io.dropwizard.jetty.MutableServletContextHandler.percent-4xx-15m", "value":0.3320844220109032,"Time":"2017-08-10\_18:11:40.461"}"}

Filter:  
date {  
match =\> ["Time","dd MMM yyyy;HH:mm:ss.SSS"]  
target =\> "Time"  
}

After applying this date filter Time is not converted to date format.

Thanks and Regards,  
E.Jones Thomas

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 14, 2017, 10:21am UTC](https://discuss.elastic.co/t/date-filter-not-working-properly/96941/2 "2017-08-14T10:21:01Z")

</div>

The date pattern "dd MMM yyyy;HH:mm:ss.SSS" obviously doesn't match the actual time format "2017-08-10\_18:11:40.461". You'll have to rearrange things a little bit. See the date filter documentation for details on what the various pieces of the date pattern mean.

Also, you are using a json codec or filter to process the input, right, so that there actually is a `Time` field to parse?

---

<div class="post-metadata">

**Author:** ![Chemse](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chemse/32/17956_2.png) [@Chemse](https://discuss.elastic.co/u/Chemse)\
**Post date:** [August 14, 2017, 10:22am UTC](https://discuss.elastic.co/t/date-filter-not-working-properly/96941/3 "2017-08-14T10:22:59Z")

</div>

try this 🙂

```
date {
     match => ["Time","YYYY-MM-dd_HH:mm:ss.SSSS"]
    target => "Time"
}
```

---

<div class="post-metadata">

**Author:** ![Jonesthomas](https://avatars.discourse-cdn.com/v4/letter/j/f4b2a3/32.png) [@Jonesthomas](https://discuss.elastic.co/u/Jonesthomas)\
**Post date:** [August 14, 2017, 10:34am UTC](https://discuss.elastic.co/t/date-filter-not-working-properly/96941/4 "2017-08-14T10:34:32Z")

</div>

> [@Chemse](#):
>
> try this 🙂
> 
> date {  
> match =\> ["Time","YYYY-MM-dd\_HH:mm:ss.SSSS"]  
> target =\> "Time"  
> }

i reindexed, tried again still in string field and \_dateparsefailure is showing in kibana.

---

<div class="post-metadata">

**Author:** ![Jonesthomas](https://avatars.discourse-cdn.com/v4/letter/j/f4b2a3/32.png) [@Jonesthomas](https://discuss.elastic.co/u/Jonesthomas)\
**Post date:** [August 14, 2017, 10:35am UTC](https://discuss.elastic.co/t/date-filter-not-working-properly/96941/5 "2017-08-14T10:35:40Z")

</div>

> [@magnusbaeck](#):
>
> The date pattern “dd MMM yyyy;HH:mm:ss.SSS” obviously doesn’t match the actual time format “2017-08-10\_18:11:40.461”. You’ll have to rearrange things a little bit. See the date filter documentation for details on what the various pieces of the date pattern mean.
> 
> Also, you are using a json codec or filter to process the input, right, so that there actually is a Time field to parse?

This is my Json-filter:  
ilter {  
json {  
source =\> "message"  
}  
json {  
source =\> "LogMsg"  
}  
date {  
match =\> ["Time","YYYY-MM-dd\_HH:mm:ss.SSSS"]  
target =\> "Time"  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 14, 2017, 11:34am UTC](https://discuss.elastic.co/t/date-filter-not-working-properly/96941/6 "2017-08-14T11:34:13Z")

</div>

Have you looked in the Logstash log for clues? When the date filter adds the `_dateparsefailure` tag it also logs a reason for it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 11, 2017, 11:34am UTC](https://discuss.elastic.co/t/date-filter-not-working-properly/96941/7 "2017-09-11T11:34:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
