# Date filter not working to set timestamp and receive logs

**URL:** <https://discuss.elastic.co/t/date-filter-not-working-to-set-timestamp-and-receive-logs/161856>\
**Category:** Logstash\
**Created:** [December 21, 2018, 2:31pm UTC](https://discuss.elastic.co/t/date-filter-not-working-to-set-timestamp-and-receive-logs/161856 "2018-12-21T14:31:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![cazorino](https://avatars.discourse-cdn.com/v4/letter/c/cc9497/32.png) [@cazorino](https://discuss.elastic.co/u/cazorino)\
**Post date:** [December 21, 2018, 2:31pm UTC](https://discuss.elastic.co/t/date-filter-not-working-to-set-timestamp-and-receive-logs/161856/1 "2018-12-21T14:31:49Z")

</div>

Hello community!

I'm facing a problem when trying to receive logs and using their date field as timestamp, following is my log example:  
`Dec 19 13:41:28 server-test smbd_audit: DOMAIN+user.fake|127.0.0.1|general|open|ok|r|Plan.xls`

If I use the following filter, everything works fine and I can get the logs, but I still cannot set the timestamp as with the value of the new field added (since the original date doesn't have a year, a new field was created):

```
filter {
  grok {
    match => { "message" => [
      "%{SYSLOGTIMESTAMP:log_timestamp} %{SYSLOGHOST:server} %{WORD:type}: %{WORD:domain}\S%{USERNAME:user}\S%{IPV4:ip}\S%{WORD:folder}\S%{WORD:status}\S%{WORD:status2}\S%{WORD:action}\S%{GREEDYDATA:file}", 
      "%{SYSLOGTIMESTAMP:log_timestamp} %{SYSLOGHOST:server} %{WORD:type}: %{WORD:domain}\S%{USERNAME:user}\S%{IPV4:ip}\S%{WORD:folder}\S%{WORD:status}\S%{WORD:status2}"
      ]
    }
    add_field => ["new_timestamp", "%{log_timestamp} 2018"]
  }
}

```

As a solution to get the new field as my default timestamp, I used the date filter like below, however it doesn't work and even worse, I stop receiving logs.

```
filter {
  grok {
    match => { "message" => [
      "%{SYSLOGTIMESTAMP:log_timestamp} %{SYSLOGHOST:server} %{WORD:type}: %{WORD:domain}\S%{USERNAME:user}\S%{IPV4:ip}\S%{WORD:folder}\S%{WORD:status}\S%{WORD:status2}\S%{WORD:action}\S%{GREEDYDATA:file}", 
      "%{SYSLOGTIMESTAMP:log_timestamp} %{SYSLOGHOST:server} %{WORD:type}: %{WORD:domain}\S%{USERNAME:user}\S%{IPV4:ip}\S%{WORD:folder}\S%{WORD:status}\S%{WORD:status2}"
      ]
    }
    add_field => ["new_timestamp", "%{log_timestamp} 2018"]
  }
  date {
      match => ["new_timestamp", "MMM d HH:mm:ss YYYY", "MMM dd HH:mm:ss YYYY"]
      timezone => "Etc/GMT" 
  }
}
```

---

<div class="post-metadata">

**Author:** ![AquaX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aquax/32/92006_2.png) [@AquaX](https://discuss.elastic.co/u/AquaX)\
**Post date:** [January 3, 2019, 3:36pm UTC](https://discuss.elastic.co/t/date-filter-not-working-to-set-timestamp-and-receive-logs/161856/2 "2019-01-03T15:36:09Z")

</div>

Very interesting as this looks like it should work... have you tried looking at the output to stdout and seeing what the JSON looks like for new\_timestamp and @timestamp?

---

<div class="post-metadata">

**Author:** ![cazorino](https://avatars.discourse-cdn.com/v4/letter/c/cc9497/32.png) [@cazorino](https://discuss.elastic.co/u/cazorino)\
**Post date:** [January 3, 2019, 4:21pm UTC](https://discuss.elastic.co/t/date-filter-not-working-to-set-timestamp-and-receive-logs/161856/3 "2019-01-03T16:21:49Z")

</div>

Not yet, but I will try to do it. I just need to get some knowledge about how to do it first. Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 31, 2019, 4:21pm UTC](https://discuss.elastic.co/t/date-filter-not-working-to-set-timestamp-and-receive-logs/161856/4 "2019-01-31T16:21:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
