# Date Mapping Parse Failure after upgrade to 7.1.1

**URL:** <https://discuss.elastic.co/t/date-mapping-parse-failure-after-upgrade-to-7-1-1/184704>\
**Category:** Elasticsearch\
**Created:** [June 7, 2019, 7:52am UTC](https://discuss.elastic.co/t/date-mapping-parse-failure-after-upgrade-to-7-1-1/184704 "2019-06-07T07:52:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![johnwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johnwood/32/78918_2.png) [@johnwood](https://discuss.elastic.co/u/johnwood)\
**Post date:** [June 7, 2019, 7:52am UTC](https://discuss.elastic.co/t/date-mapping-parse-failure-after-upgrade-to-7-1-1/184704/1 "2019-06-07T07:52:45Z")

</div>

We have just upgraded to 7.1.1 (from 6.7) on the Elastic Cloud service.

Our previously happy logstash is now erroring out with a date related parsing issue when trying to put a date field into ES.

The error we get is:

```
 [2019-06-07T17:22:55,068][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"pnm-2019.06.07", :_type=>"_doc", :routing=>nil}, #<LogStash::Event:0x1096275e>], :response=>{"index"=>{"_index"=>"pnm-2019.06.07", "_type"=>"_doc", "_id"=>"58fRMGsBjCggiYigqPIl", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [AgentTime] of type [date] in document with id '58fRMGsBjCggiYigqPIl'", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"failed to parse date field [2019.06.07 17:22:54.626 GMT+10:00] with format [yyyy.MM.dd HH:mm:ss.SSS 'GMT'Z]", "caused_by"=>{"type"=>"date_time_parse_exception", "reason"=>"Text '2019.06.07 17:22:54.626 GMT+10:00' could not be parsed at index 27"}}}}}}

```

In short we are trying to get this date into ES: "2019.06.07 17:22:54.626 GMT+10:00"

The mapping in ES looks like this:  
"AgentTime": {  
"type": "date",  
"format": "yyyy.MM.dd HH:mm:ss.SSS 'GMT'Z"  
},

Any advice or pointers would be appreciated

Thanks!

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 7, 2019, 8:25am UTC](https://discuss.elastic.co/t/date-mapping-parse-failure-after-upgrade-to-7-1-1/184704/2 "2019-06-07T08:25:46Z")

</div>

I'm pretty sure @spinscale can help.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 7, 2019, 12:30pm UTC](https://discuss.elastic.co/t/date-mapping-parse-failure-after-upgrade-to-7-1-1/184704/3 "2019-06-07T12:30:30Z")

</div>

Try this as a format: `"yyyy.MM.dd HH:mm:ss.SSS 'GMT'XXX"` under 7.x

Your format should have been logged as a deprecation since 6.7, but has only recently been added to the 6.8 branch. See [this PR](https://github.com/elastic/elasticsearch/pull/41956)

hope this helps!

---

<div class="post-metadata">

**Author:** ![johnwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johnwood/32/78918_2.png) [@johnwood](https://discuss.elastic.co/u/johnwood)\
**Post date:** [June 9, 2019, 10:05am UTC](https://discuss.elastic.co/t/date-mapping-parse-failure-after-upgrade-to-7-1-1/184704/4 "2019-06-09T10:05:31Z")

</div>

Wow - thanks so much, just updated our mapping and 'boink' we are indexing again. Thanks so much - if you get to Sydney I owe you a beer!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 7, 2019, 10:05am UTC](https://discuss.elastic.co/t/date-mapping-parse-failure-after-upgrade-to-7-1-1/184704/5 "2019-07-07T10:05:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
