# Date Inconsistency between logstash stout and elastic search

**URL:** <https://discuss.elastic.co/t/date-inconsistency-between-logstash-stout-and-elastic-search/208237>\
**Category:** Logstash\
**Created:** [November 17, 2019, 9:28pm UTC](https://discuss.elastic.co/t/date-inconsistency-between-logstash-stout-and-elastic-search/208237 "2019-11-17T21:28:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [November 17, 2019, 9:28pm UTC](https://discuss.elastic.co/t/date-inconsistency-between-logstash-stout-and-elastic-search/208237/1 "2019-11-17T21:28:35Z")

</div>

Hi, I have a folder with multiple files called disco\_[date], when I run the comand bin/logstash -f /etc/logstash/conf.d/disco.conf and output only the stdout the dates are ok, they work and are shown in the timestamp,

![image](https://us1.discourse-cdn.com/elastic/original/3X/8/b/8baa40c59c747ca60d96f625f101f385d7d6320f.png)

But when when I try to index them in elastic, in kibana are shown empty, and the timestamp is the date and hour when I run the command.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/e/9e79565b6f4b7500836106d1ab070298d0b02ef6.png)

Any ideas why this is happening?

Is not removing the horayfecha field also.

UPDATE: I just realize its only the index for the current day that gives problems, I just re-test the grok and it works fine with the logs, but in kibana the tine stamp is corrupt...dont know whats is happening!

```
input {
            file {
                    path => "/opt/logs/disco*"
    # path => "/opt/logs/disco_2019_11_16.log"
                    start_position => "beginning"
                    sincedb_path => "/dev/null"
            }
    }

filter {
        grok {
                match => { "message" => "%{TIME:hora}\s%{DATA:fecha}\s%{DATA:status}\s%{DATA:server} (FileSystems%{DATA:FS}Available=%{NUMBER:Available}|FileSy$

        }

        mutate {
                add_field => {
                        "origen" => "alpha"
                        "horayfecha" => "%{hora} %{fecha}"
                }

                convert => {
                        "Available" => "float"
                        "pctje" => "integer"
                }
        }

        date {
                match => ["horayfecha", "HH:mm:ss MM/dd/YYYY"]
                target => "@timestamp"
                remove_field => ["horayfecha"]
        }

}

output {

        elasticsearch {
                hosts => ["foo:9200"]
                index => "discos-%{+YYYY.MM.dd}"
        }

# stdout { codec => rubydebug }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 18, 2019, 12:02am UTC](https://discuss.elastic.co/t/date-inconsistency-between-logstash-stout-and-elastic-search/208237/2 "2019-11-18T00:02:46Z")

</div>

> [@Incauto](#):
>
> Any ideas why this is happening?

The most likely explanation is that the grok does not match. Do you get \_grokparsefailure tags? What does the raw message look like?

---

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [November 18, 2019, 12:52am UTC](https://discuss.elastic.co/t/date-inconsistency-between-logstash-stout-and-elastic-search/208237/3 "2019-11-18T00:52:37Z")

</div>

Hi Badger, the grok works, I've tried several lines of the logs, and when I use standard output instead of the elastic output, it works....Question, just one bad parsed line can result in this problems? is there a way using a conditional to avoid this?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 16, 2019, 12:52am UTC](https://discuss.elastic.co/t/date-inconsistency-between-logstash-stout-and-elastic-search/208237/4 "2019-12-16T00:52:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
