# Date parser in pipeline ignores half of the day

**URL:** https://discuss.elastic.co/t/date-parser-in-pipeline-ignores-half-of-the-day/166362
**Category:** Elasticsearch
**Created:** [January 30, 2019, 1:30pm UTC](https://discuss.elastic.co/t/date-parser-in-pipeline-ignores-half-of-the-day/166362 "2019-01-30T13:30:51Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![k-troska](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/k-troska/32/67374_2.png) [@k-troska](https://discuss.elastic.co/u/k-troska)
#### Post date: [January 30, 2019, 1:30pm UTC](https://discuss.elastic.co/t/date-parser-in-pipeline-ignores-half-of-the-day/166362/1 "2019-01-30T13:30:52Z")

</div>

Hi,  
I have problem that filebeat is logging incorrect time when parasing agains time of the day.  
Example:

> {  
> "pipeline": {  
> "version": 1,  
> "processors": [  
> {  
> "grok": {  
> "field": "message",  
> "patterns": [  
> "%{ADHOC\_TIME:adhoc.timestamp}%{SPACE}%{LOGLEVEL:adhoc.level}%{SPACE}%{JAVACLASS:adhoc.class}%{SPACE}-%{SPACE},%{SPACE}MTU%{NUMBER:adhoc.mtu},%{SPACE}%{NUMBER:adhoc.report.accountid},%{SPACE}%{NUMBER:adhoc.report.userid},%{SPACE}%{WORD:adhoc.report.format},%{SPACE}%{GREEDYDATA:adhoc.report.times}",  
> "%{ADHOC\_TIME:adhoc.timestamp}%{SPACE}%{LOGLEVEL:adhoc.level}%{SPACE}%{JAVACLASS:adhoc.class}%{SPACE}-%{SPACE}%{GREEDYMULTILINE:jboss.server.trace.full}"  
> ],  
> "pattern\_definitions": {  
> "ADHOC\_TIME": "%{MONTH} %{MONTHDAY}, %{YEAR} %{TIME} ([AP]M)",  
> "GREEDYMULTILINE": "(.|\n)\*"  
> }  
> }  
> },  
> {  
> "date": {  
> "field": "adhoc.timestamp",  
> "target\_field": "@timestamp",  
> "timezone": "{{ beat.timezone }}",  
> "formats": [  
> "MMM dd, yyyy HH:mm:ss aa"  
> ]  
> }  
> },  
> {  
> "remove": {  
> "field": [  
> "message"  
> ]  
> }  
> }  
> ],  
> "on\_failure": [  
> {  
> "set": {  
> "field": "error.message",  
> "value": "{{ \_ingest.on\_failure\_message }}"  
> }  
> }  
> ],  
> "description": "Pipeline for parsing report (adhoc) server logs"  
> },  
> "docs": [  
> {  
> "\_source": {  
> "@timestamp": "2019-01-30T12:58:15.489Z",  
> "@metadata": {  
> "beat": "filebeat",  
> "type": "doc",  
> "version": "6.5.4",  
> "pipeline": "filebeat-6.5.4-adhoc-report-pipeline"  
> },  
> "offset": 485398,  
> "tags": [  
> "adhoc"  
> ],  
> "message": "Jan 30, 2019 01:58:11 PM DEBUG report.internal.impl.ReportImpl - , MTU1232, 1, 18, HTMLPREVIEW, 31, 2, 4, 0, 1, 0, 55 ",  
> "source": "adhocreport.log",  
> "fileset": {  
> "module": "adhoc",  
> "name": "report"  
> },  
> "prospector": {  
> "type": "log"  
> },  
> "input": {  
> "type": "log"  
> },  
> "beat": {  
> "timezone": "+01:00",  
> "hostname": "adhoc",  
> "version": "6.5.4",  
> "name": "adhoc"  
> },  
> "host": {  
> "name": "adhoc"  
> }  
> }  
> }  
> ]  
> }

And the output is:

> {  
> "docs" : [  
> {  
> "doc" : {  
> "\_index" : "\_index",  
> "\_type" : "\_type",  
> "\_id" : "\_id",  
> "\_source" : {  
> "offset" : 485398,  
> "@metadata" : {  
> "pipeline" : "filebeat-6.5.4-adhoc-report-pipeline",  
> "beat" : "filebeat",  
> "type" : "doc",  
> "version" : "6.5.4"  
> },  
> "prospector" : {  
> "type" : "log"  
> },  
> "source" : "adhocreport.log",  
> "fileset" : {  
> "name" : "report",  
> "module" : "adhoc"  
> },  
> "tags" : [  
> "adhoc"  
> ],  
> "input" : {  
> "type" : "log"  
> },  
> "@timestamp" : "2019-01-30T01:58:11.000+01:00",  
> "beat" : {  
> "name" : "adhoc",  
> "hostname" : "adhoc",  
> "version" : "6.5.4",  
> "timezone" : "+01:00"  
> },  
> "host" : {  
> "name" : "adhoc"  
> },  
> "adhoc" : {  
> "report" : {  
> "format" : "HTMLPREVIEW",  
> "accountid" : "1",  
> "times" : "31, 2, 4, 0, 1, 0, 55 ",  
> "userid" : "18"  
> },  
> "level" : "DEBUG",  
> "class" : "report.internal.impl.ReportImpl",  
> "timestamp" : "Jan 30, 2019 01:58:11 PM",  
> "mtu" : "1232"  
> }  
> },  
> "\_ingest" : {  
> "timestamp" : "2019-01-30T13:25:23.508Z"  
> }  
> }  
> }  
> ]  
> }

In short timestamp is set to: 2019-01-30T01:58:11.000+01:00 when time is: Jan 30, 2019 01:58:11 PM which should end up as: 2019-01-30T13:58:11.000+01:00. Is this bug or am I missing something?  
test:

> curl -X POST [http://localhost:9200/\_ingest/pipeline/\_simulate?pretty](http://localhost:9200/_ingest/pipeline/_simulate?pretty)

I am using elasticsearch-oss and filebeat 6.5.4

---

<div class="post-metadata">

### Author: ![k-troska](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/k-troska/32/67374_2.png) [@k-troska](https://discuss.elastic.co/u/k-troska)
#### Post date: [January 30, 2019, 1:59pm UTC](https://discuss.elastic.co/t/date-parser-in-pipeline-ignores-half-of-the-day/166362/2 "2019-01-30T13:59:43Z")

</div>

> [@k-troska](#):
>
> "MMM dd, yyyy HH:mm:ss aa"

Ok found it this format should be:

> "MMM dd, yyyy hh:mm:ss aa"  
> so hh insted of HH.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 27, 2019, 1:59pm UTC](https://discuss.elastic.co/t/date-parser-in-pipeline-ignores-half-of-the-day/166362/3 "2019-02-27T13:59:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
