# Date is not being parsed with AM / PM

**URL:** https://discuss.elastic.co/t/date-is-not-being-parsed-with-am-pm/256852
**Category:** Logstash
**Tags:** elastic-stack-monitoring
**Created:** [November 27, 2020, 8:43am UTC](https://discuss.elastic.co/t/date-is-not-being-parsed-with-am-pm/256852 "2020-11-27T08:43:08Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![shani](https://avatars.discourse-cdn.com/v4/letter/s/e95f7d/32.png) [@shani](https://discuss.elastic.co/u/shani)
#### Post date: [November 27, 2020, 8:43am UTC](https://discuss.elastic.co/t/date-is-not-being-parsed-with-am-pm/256852/1 "2020-11-27T08:43:08Z")

</div>

HI, this is my config file. I want to extract date from the log and want to create two field like

- time\_mentioned\_in\_log
- time\_when\_log\_was\_received\_at\_logstash

Raw Log:

3/2/2020 10:14 AM TYPE=Information USER= COMP=ABCXYZ.local SORC=Dummy CATG=(0) EVID=1 MESG=some\_msg\_here

configuration file:

```
input {

```

file {  
path =\> "/etc/logstash/files/time.log"  
start\_position =\> beginning  
sincedb\_path =\> "/dev/null"  
}  
}

filter {  
date {  
match =\> ["message", "d/M/YYYY HH:mm a"]  
target =\> "logtimestamp"  
}  
}

output {  
stdout { codec =\> rubydebug }  
}

Please help me.

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [November 27, 2020, 1:49pm UTC](https://discuss.elastic.co/t/date-is-not-being-parsed-with-am-pm/256852/2 "2020-11-27T13:49:58Z")

</div>

The pattern in the date filter has to consume the entire field, so for that message you would have to use

```
date { match => ["[message]", "d/M/YYYY HH:mm a' TYPE=Information USER= COMP=ABCXYZ.local SORC=Dummy CATG=(0) EVID=1 MESG=some_msg_here'" ] }

```

Use dissect or grok to extract the timestamp from the message and then use a date filter to parse that.

---

<div class="post-metadata">

### Author: ![shani](https://avatars.discourse-cdn.com/v4/letter/s/e95f7d/32.png) [@shani](https://discuss.elastic.co/u/shani)
#### Post date: [November 27, 2020, 4:05pm UTC](https://discuss.elastic.co/t/date-is-not-being-parsed-with-am-pm/256852/3 "2020-11-27T16:05:34Z")

</div>

Hi Sir,

I'm unable to understand what's missing here. Dissect or Grok gets failed when I use to parse it. Like dissect is getting failed here

```
input {
file {
path => "/etc/logstash/files/time.log"
start_position => beginning
sincedb_path => "/dev/null"
}
}

filter {
dissect {
  mapping => {
    "message" => "%{log_time} TYPE=%{[event][type]} USER=%{[user][name]} COMP=%{[most][hostname]} SORC=%{[event][module]} CATG=%{[event][category]} EVID=%{[event][id]} MESG=%{[custom][message]}"
  }
}
date {
match => ["log_time", "d/M/YYYY HH:mm a"]
target => "[event][created]"
}  
}

output {
stdout { codec => rubydebug }
}

```

Input files contains the logs  
3/2/2020 10:16 AM TYPE=Information USER= COMP=ABC.xyz.local SORC=Software Protection Platform Service CATG=(0) EVID=1003 MESG=The Software Protection service has completed licensing status check. Application Id=0ff1ce15-a989-479d-af46-f275c6370663 Licensing Status= 1: 149dbce7-a48e-44db-8364-a53386cd4580, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 3 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 9 0x00000000 46 34702)(?)(?)])(1 )(2 )(3 )]

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [November 27, 2020, 4:21pm UTC](https://discuss.elastic.co/t/date-is-not-being-parsed-with-am-pm/256852/4 "2020-11-27T16:21:45Z")

</div>

> [@shani](#):
>
> ```auto
> dissect { mapping => { "message" => "%{log_time} TYPE=%{[event][type]} ...
> 
> ```

That is not going to match. It says that [message] should contain characters that are not space (the delimiter), followed by a space, followed by the literal string TYPE=. That's not what you have. Try

```
dissect { mapping => { "message" => "%{log_time} %{+log_time} %{+log_time} TYPE=%{[event][type]}

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 25, 2020, 4:21pm UTC](https://discuss.elastic.co/t/date-is-not-being-parsed-with-am-pm/256852/5 "2020-12-25T16:21:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
