# Date format for YYYY-mm-dd HH:mm:ss,SSS?

**URL:** <https://discuss.elastic.co/t/date-format-for-yyyy-mm-dd-hh-mm-ss-sss/80702>\
**Category:** Logstash\
**Created:** [March 30, 2017, 2:55pm UTC](https://discuss.elastic.co/t/date-format-for-yyyy-mm-dd-hh-mm-ss-sss/80702 "2017-03-30T14:55:45Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![ZillaG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zillag/32/10505_2.png) [@ZillaG](https://discuss.elastic.co/u/ZillaG)\
**Post date:** [March 30, 2017, 2:55pm UTC](https://discuss.elastic.co/t/date-format-for-yyyy-mm-dd-hh-mm-ss-sss/80702/1 "2017-03-30T14:55:45Z")

</div>

I looked at the [Elasticsearch date format docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-date-format.html) after reading [this post](https://discuss.elastic.co/t/logdate-field-with-format-yyyy-mm-dd-hh-mm-ss-sss-converted-to-2015-01-01t00-33-33-000z/29826) and can't find the format for a date of the form YYYY-mm-dd HH:mm:ss,SSSS, e.g., 2017-03-29 10:00:00,123, where there's a comma for the milliseconds part. The log looks like

`2017-03-29 10:00:00,123 INFO [com.company.app] This is a log`

and my Grok filter to get the log date is

```
filter {
  if [type] == "artim-learning" {
    grok {
      match => {
        "message" => [
          "%{TIMESTAMP_ISO8601:logdate} ....other fields..."
        }
      }
    }
  }
}

```

The default Logstash mapping maps "logdate" as a string. If I want to map it as a date, what format do i use?

Thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 30, 2017, 3:07pm UTC](https://discuss.elastic.co/t/date-format-for-yyyy-mm-dd-hh-mm-ss-sss/80702/2 "2017-03-30T15:07:20Z")

</div>

Normally one uses the date filter to parse a timestamp and produce an ISO8601 timestamp that Elasticsearch automatically treats as a date.

---

<div class="post-metadata">

**Author:** ![ZillaG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zillag/32/10505_2.png) [@ZillaG](https://discuss.elastic.co/u/ZillaG)\
**Post date:** [March 30, 2017, 3:21pm UTC](https://discuss.elastic.co/t/date-format-for-yyyy-mm-dd-hh-mm-ss-sss/80702/3 "2017-03-30T15:21:21Z")

</div>

So like this?

```
filter {
  if [type] == "artim-learning" {
    grok {
      match => {
        "message" => [
          "%{TIMESTAMP_ISO8601:logdate} ....other fields..."
        }
      }
    }
    date {
      match => ["logdate", "YYYY-mm-dd HH:mm:ss,SSSS"]
    }
  }
}

```

Thanks!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 30, 2017, 3:38pm UTC](https://discuss.elastic.co/t/date-format-for-yyyy-mm-dd-hh-mm-ss-sss/80702/4 "2017-03-30T15:38:20Z")

</div>

Close: YYYY- **MM** -dd HH:mm:ss, **SSS**

---

<div class="post-metadata">

**Author:** ![ZillaG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zillag/32/10505_2.png) [@ZillaG](https://discuss.elastic.co/u/ZillaG)\
**Post date:** [March 30, 2017, 3:41pm UTC](https://discuss.elastic.co/t/date-format-for-yyyy-mm-dd-hh-mm-ss-sss/80702/5 "2017-03-30T15:41:15Z")

</div>

@magnusbaeck, thanks!

---

<div class="post-metadata">

**Author:** ![ZillaG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zillag/32/10505_2.png) [@ZillaG](https://discuss.elastic.co/u/ZillaG)\
**Post date:** [March 31, 2017, 2:47pm UTC](https://discuss.elastic.co/t/date-format-for-yyyy-mm-dd-hh-mm-ss-sss/80702/6 "2017-03-31T14:47:30Z")

</div>

I added the date filter, but I still see this when I query the mapping

```
date {
  match => ["logdate", "YYYY-MM-dd HH:mm:ss,SSS"]
}

      "logdate" : {
        "type" : "string",
        "norms" : {
          "enabled" : false
        },
        "fielddata" : {
          "format" : "disabled"
        },
        "fields" : {
          "raw" : {
            "type" : "string",
            "index" : "not_analyzed",
            "ignore_above" : 256
          }
        }
      },

```

One discrepancy is the docs show the year as lowercase "y" vs. uppercase "Y" for the year?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 3, 2017, 5:05am UTC](https://discuss.elastic.co/t/date-format-for-yyyy-mm-dd-hh-mm-ss-sss/80702/7 "2017-04-03T05:05:11Z")

</div>

> I added the date filter, but I still see this when I query the mapping

Did you create a new index? Mappings of existing indexes can't be changed.

> One discrepancy is the docs show the year as lowercase "y" vs. uppercase "Y" for the year?

Either will work.

---

<div class="post-metadata">

**Author:** ![ZillaG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zillag/32/10505_2.png) [@ZillaG](https://discuss.elastic.co/u/ZillaG)\
**Post date:** [April 3, 2017, 12:15pm UTC](https://discuss.elastic.co/t/date-format-for-yyyy-mm-dd-hh-mm-ss-sss/80702/8 "2017-04-03T12:15:00Z")

</div>

I create a new daily index, yes.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 3, 2017, 12:27pm UTC](https://discuss.elastic.co/t/date-format-for-yyyy-mm-dd-hh-mm-ss-sss/80702/9 "2017-04-03T12:27:34Z")

</div>

The date filter by defaults put the parsed timestamp in the [default @timestamp field](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html#plugins-filters-date-target).

---

<div class="post-metadata">

**Author:** ![ZillaG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zillag/32/10505_2.png) [@ZillaG](https://discuss.elastic.co/u/ZillaG)\
**Post date:** [April 3, 2017, 12:59pm UTC](https://discuss.elastic.co/t/date-format-for-yyyy-mm-dd-hh-mm-ss-sss/80702/10 "2017-04-03T12:59:44Z")

</div>

@Christian_Dahlqvist, how can I ADDITIONALY put the date filter's parsed timestamp in my **logdate** field?

---

<div class="post-metadata">

**Author:** ![ZillaG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zillag/32/10505_2.png) [@ZillaG](https://discuss.elastic.co/u/ZillaG)\
**Post date:** [April 4, 2017, 1:41pm UTC](https://discuss.elastic.co/t/date-format-for-yyyy-mm-dd-hh-mm-ss-sss/80702/11 "2017-04-04T13:41:25Z")

</div>

@Christian_Dahlqvist, I got it to work with this filter. Your hint about @timestamp being the default gave me the idea to set the target. Thanks!

```
date {
  match => ["logdate", "YYYY-MM-dd HH:mm:ss,SSS"]
  target => "logdate"
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 2, 2017, 1:41pm UTC](https://discuss.elastic.co/t/date-format-for-yyyy-mm-dd-hh-mm-ss-sss/80702/12 "2017-05-02T13:41:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
