# Date Filter not working with IST

**URL:** <https://discuss.elastic.co/t/date-filter-not-working-with-ist/165219>\
**Category:** Logstash\
**Created:** [January 22, 2019, 11:02am UTC](https://discuss.elastic.co/t/date-filter-not-working-with-ist/165219 "2019-01-22T11:02:25Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Harsh\_Sharma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harsh_sharma/32/32093_2.png) [@Harsh\_Sharma](https://discuss.elastic.co/u/Harsh_Sharma)\
**Post date:** [January 22, 2019, 11:02am UTC](https://discuss.elastic.co/t/date-filter-not-working-with-ist/165219/1 "2019-01-22T11:02:25Z")

</div>

Hi,

I'm using logstash 6.5.4. Below is my sample log & input file -  
Sample log -  
**2019-01-12 13:10:38 IST,9898989898,HHH-444**  
**2019-01-12 13:11:38 IST,9898989897,HHH-555**

```
filter{

        if "test111" in [log_type] {
                csv{
                        columns => ["time","Msisdn","segment"]
                }
                date {
                match => ["time", "yyyy-MM-dd HH:mm:ss ZZZ"]
                target => "log_timestamp"
                remove_field => "time"
                }
        }
}

```

instead of ZZZ in match I have tried 'z' 'Z' and left it blank too. I got index in Kibana but getting only option of @timestamp in Time Filter field name.

What am I missing to see "log\_timestamp" in Time Filter field name?  
Please suggest. Thanks

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [January 22, 2019, 11:12am UTC](https://discuss.elastic.co/t/date-filter-not-working-with-ist/165219/2 "2019-01-22T11:12:39Z")

</div>

Hello @Harsh_Sharma,

Please use  
timezone =\> "Asia/Kolkata"

after target

Regards  
Shrikant

---

<div class="post-metadata">

**Author:** ![Harsh\_Sharma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harsh_sharma/32/32093_2.png) [@Harsh\_Sharma](https://discuss.elastic.co/u/Harsh_Sharma)\
**Post date:** [January 22, 2019, 11:34am UTC](https://discuss.elastic.co/t/date-filter-not-working-with-ist/165219/3 "2019-01-22T11:34:50Z")

</div>

Hi @shrikantgulia

I have already tried it & checked once again now too but same result.

```
filter{

        if "test111" in [log_type] {
                csv{
                        columns => ["time","Msisdn","segment"]
                }
                date {
                match => ["time", "yyyy-MM-dd HH:mm:ss ZZZ"]
                target => "log_timestamp"
                timezone => "Asia/Kolkata"
                remove_field => "time"
                }
        }
}

```

in Time Filter field I'm getting default option of @timestamp.  
I'm struggling how to handle this 'IST' part.  
Sample log -  
**2019-01-12 13:10:38 IST,9898989898,HHH-444**

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [January 22, 2019, 11:49am UTC](https://discuss.elastic.co/t/date-filter-not-working-with-ist/165219/4 "2019-01-22T11:49:39Z")

</div>

@Harsh_Sharma @shrikantgulia

Please confirm that his works.

It is my understanding that IST is one of the ambiguous abbreviations and so the Java Joda library that we use behind the scenes can't determine clearly what offset to use. See [https://www.timeanddate.com/time/zones/](https://www.timeanddate.com/time/zones/)

In the past, I have advised people to replace the `IST` with `Asia/Kolkata` before the date filter attempts to convert the string.

```auto
input {
  generator {
    lines => ['2019-01-12 13:10:38 IST,9898989898,HHH-444']
    count => 1
  }
}

filter {
  csv{
    columns => ["time","Msisdn","segment"]
  }
  mutate {
    gsub => ["[time]", "IST$", "Asia/Kolkata"]
  }
  date {
    match => ["time", "yyyy-MM-dd HH:mm:ss ZZZ", "yyyy-MM-dd HH:mm:ss Z"]
    target => "log_timestamp"
  }
}

output {
  stdout { codec => rubydebug }
}

```

Gives:

```auto
{
          "time" => "2019-01-12 13:10:38 Asia/Kolkata",
      "sequence" => 0,
       "message" => "2019-01-12 13:10:38 IST,9898989898,HHH-444",
          "host" => "Elastics-MacBook-Pro.local",
       "segment" => "HHH-444",
      "@version" => "1",
        "Msisdn" => "9898989898",
 "log_timestamp" => 2019-01-12T07:40:38.000Z,
    "@timestamp" => 2019-01-22T11:46:56.321Z
}

```

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [January 22, 2019, 12:13pm UTC](https://discuss.elastic.co/t/date-filter-not-working-with-ist/165219/5 "2019-01-22T12:13:04Z")

</div>

FYI [https://github.com/logstash-plugins/logstash-filter-date/issues/128](https://github.com/logstash-plugins/logstash-filter-date/issues/128)

---

<div class="post-metadata">

**Author:** ![Harsh\_Sharma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harsh_sharma/32/32093_2.png) [@Harsh\_Sharma](https://discuss.elastic.co/u/Harsh_Sharma)\
**Post date:** [January 23, 2019, 7:10am UTC](https://discuss.elastic.co/t/date-filter-not-working-with-ist/165219/6 "2019-01-23T07:10:58Z")

</div>

Hi @guyboertje

Thanks for the update. Finally got success after making a little bit change.

```
csv{
                        columns => ["timelog","Msisdn","segment"]
                }
                mutate {
                 gsub => [
                        "timelog", " IST$", ""
                 ]
                 }
                date {
                match => ["timelog", "yyyy-MM-dd HH:mm:ss"]
                target => "log_timestamp"
                remove_field => timelog
                }
                }
        }
```

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [January 23, 2019, 9:14am UTC](https://discuss.elastic.co/t/date-filter-not-working-with-ist/165219/7 "2019-01-23T09:14:00Z")

</div>

OK, that works too but you should **now** set the timezone in the date filter as the time portion is definitely not UTC.

(For future readers) You can remove the TZ abbreviation only if **all** your timestamp strings are expressed in one timezone. If you get a mix of TZ abbreviations (as one might get in global centralised logging) then removing the TZ abbreviation is problematic.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2019, 9:14am UTC](https://discuss.elastic.co/t/date-filter-not-working-with-ist/165219/8 "2019-02-20T09:14:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
