# Date format in elasticsearch

**URL:** <https://discuss.elastic.co/t/date-format-in-elasticsearch/44004>\
**Category:** Elasticsearch\
**Created:** [March 10, 2016, 10:14am UTC](https://discuss.elastic.co/t/date-format-in-elasticsearch/44004 "2016-03-10T10:14:10Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![pecwich](https://avatars.discourse-cdn.com/v4/letter/p/bc79bd/32.png) [@pecwich](https://discuss.elastic.co/u/pecwich)\
**Post date:** [March 10, 2016, 10:14am UTC](https://discuss.elastic.co/t/date-format-in-elasticsearch/44004/1 "2016-03-10T10:14:10Z")

</div>

While sending logs from logstash to elasticsearch, How can I specify my date within the logs to "date" format, rather than just a string?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 12, 2016, 2:24am UTC](https://discuss.elastic.co/t/date-format-in-elasticsearch/44004/2 "2016-03-12T02:24:03Z")

</div>

You should be groking your field in LS and then applying a date filter on it, that should work and it'll be standardised.  
Otherwise setup a template that matches the field.

---

<div class="post-metadata">

**Author:** ![pecwich](https://avatars.discourse-cdn.com/v4/letter/p/bc79bd/32.png) [@pecwich](https://discuss.elastic.co/u/pecwich)\
**Post date:** [March 14, 2016, 5:07am UTC](https://discuss.elastic.co/t/date-format-in-elasticsearch/44004/3 "2016-03-14T05:07:00Z")

</div>

Can you give an example of how can I apply the date filter?

For example, in my use case, the date format is like: 11 Mar 2016 02:15:46,853

Right now, I am using it like a string. I want it to be of date format which I can apply using either a template, or the date filter like you just said. How can I do that?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 14, 2016, 5:57am UTC](https://discuss.elastic.co/t/date-format-in-elasticsearch/44004/4 "2016-03-14T05:57:36Z")

</div>

[https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html) will get you sorted!

---

<div class="post-metadata">

**Author:** ![pecwich](https://avatars.discourse-cdn.com/v4/letter/p/bc79bd/32.png) [@pecwich](https://discuss.elastic.co/u/pecwich)\
**Post date:** [March 14, 2016, 6:39am UTC](https://discuss.elastic.co/t/date-format-in-elasticsearch/44004/5 "2016-03-14T06:39:02Z")

</div>

I am parsing my logs using the date format, but it is not appearing as a field in the logstash output.

filter {  
grok{  
/\* parsing of the entire log message \*/  
}  
date {  
match =\> ["logdate", "dd MMM YYYY HH:mm:ss,SSS"]  
}  
}

---

<div class="post-metadata">

**Author:** ![pecwich](https://avatars.discourse-cdn.com/v4/letter/p/bc79bd/32.png) [@pecwich](https://discuss.elastic.co/u/pecwich)\
**Post date:** [March 14, 2016, 7:18am UTC](https://discuss.elastic.co/t/date-format-in-elasticsearch/44004/6 "2016-03-14T07:18:47Z")

</div>

Can you let me know the solution to my specific problem, i.e. , the date format?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:08pm UTC](https://discuss.elastic.co/t/date-format-in-elasticsearch/44004/7 "2017-07-05T23:08:44Z")

</div>


