# Date Formatting of

**URL:** https://discuss.elastic.co/t/date-formatting-of/53087
**Category:** Logstash
**Created:** [June 17, 2016, 4:14am UTC](https://discuss.elastic.co/t/date-formatting-of/53087 "2016-06-17T04:14:06Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![kunalp](https://avatars.discourse-cdn.com/v4/letter/k/59ef9b/32.png) [@kunalp](https://discuss.elastic.co/u/kunalp)
#### Post date: [June 17, 2016, 4:14am UTC](https://discuss.elastic.co/t/date-formatting-of/53087/1 "2016-06-17T04:14:06Z")

</div>

I need parse date in logstash of format [03/Apr/2016:10:35:57 +0530] .  
This is from Weblogic Access logs.

How to do it.

Regards,  
Kunal

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [June 17, 2016, 5:33am UTC](https://discuss.elastic.co/t/date-formatting-of/53087/2 "2016-06-17T05:33:44Z")

</div>

The first configuration example at [https://www.elastic.co/guide/en/logstash/current/config-examples.html](https://www.elastic.co/guide/en/logstash/current/config-examples.html) is very very similar to what you want to do.

---

<div class="post-metadata">

### Author: ![kunalp](https://avatars.discourse-cdn.com/v4/letter/k/59ef9b/32.png) [@kunalp](https://discuss.elastic.co/u/kunalp)
#### Post date: [June 17, 2016, 8:04am UTC](https://discuss.elastic.co/t/date-formatting-of/53087/3 "2016-06-17T08:04:12Z")

</div>

Still I a facing issue.Please look at the following.  
---Configuration File----  
input{  
file  
{  
path=\>"/home/kunal/ELK/logstash-2.2.2/bin/date.txt"  
start\_position =\> beginning  
ignore\_older =\> 0  
}  
}  
filter  
{  
grok{  
#patterns\_dir=\> " /home/kunal/ELK/logstash-2.2.2/patterns/patterns"  
match =\> {"Date"=\>"[%{HTTPDATE:time}]"}  
}

# date{

# match =\> ["time","dd/mm/yyyy:HH:mm:ss Z"]

# }

# } output{ stdout{ codec=\> rubydebug } }

e.g date format file contents

[15/May/2016:12:16:23]  
[15/May/2016:12:16:23]

=======================================================

Logstash Output

/ELK/logstash-2.2.2/bin$ ./logstash agent -f httpDate.conf  
Settings: Default pipeline workers: 1  
Logstash startup completed  
{  
"message" =\> "[15/May/2016:12:16:23]",  
"@version" =\> "1",  
"@timestamp" =\> "2016-06-17T07:07:38.102Z",  
"path" =\> "/home/kunal/ELK/logstash-2.2.2/bin/date.txt",  
"host" =\> "localhost",  
"tags" =\> [  
**[0] "\_grokparsefailure"**  
]  
}

================================================

I think I am doing some small mistake..I am begginer to ELK.

Any suggestion on the same.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [June 17, 2016, 8:11am UTC](https://discuss.elastic.co/t/date-formatting-of/53087/4 "2016-06-17T08:11:39Z")

</div>

Three problems:

- The field with the date is in your case `message`, not `time` as you've configured your date filter.
- The `message` field contains square brackets but your date pattern doesn't.
- The date pattern includes "Z" but there's no timezone in the `message` field.

---

<div class="post-metadata">

### Author: ![kunalp](https://avatars.discourse-cdn.com/v4/letter/k/59ef9b/32.png) [@kunalp](https://discuss.elastic.co/u/kunalp)
#### Post date: [June 17, 2016, 9:05am UTC](https://discuss.elastic.co/t/date-formatting-of/53087/5 "2016-06-17T09:05:48Z")

</div>

Hi Magnus Bäck,

Thank you very much.....

Last 3 suggestion solved it.

After commenting GROK pattern every things worked fine.

Now If I am having log pattern which is combination of Text / data as well as date information ,then i need to use grok as well ...m i right.?..e.g weblogic or websphere or apache logs.....

Regards,  
Kunal

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [June 17, 2016, 10:39am UTC](https://discuss.elastic.co/t/date-formatting-of/53087/6 "2016-06-17T10:39:02Z")

</div>

Yes, grok is a common tool to extract fields from text. Most Logstash configuration will contain at least one grok filter.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 4:52am UTC](https://discuss.elastic.co/t/date-formatting-of/53087/7 "2017-07-06T04:52:15Z")

</div>


