# Dateparse failure using the date filter

**URL:** <https://discuss.elastic.co/t/dateparse-failure-using-the-date-filter/237692>\
**Category:** Logstash\
**Created:** [June 18, 2020, 6:57pm UTC](https://discuss.elastic.co/t/dateparse-failure-using-the-date-filter/237692 "2020-06-18T18:57:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![marco2005](https://avatars.discourse-cdn.com/v4/letter/m/b5ac83/32.png) [@marco2005](https://discuss.elastic.co/u/marco2005)\
**Post date:** [June 18, 2020, 6:57pm UTC](https://discuss.elastic.co/t/dateparse-failure-using-the-date-filter/237692/1 "2020-06-18T18:57:07Z")

</div>

I have a log line

`Thu Jun 18 08:01:42 CEST 2020|{"timestamp":1592460102635,"caller":"test.customer@customer1","action":"LOGIN","message":"ID000066 User [test.customer@customer1] logged in successfully."}`

This is my filter:

```
filter {
    dissect {
        mapping => {
            "message" => "%{log_timestamp}|%{data}"
        }
    }
    mutate {
        gsub => ["data","[\\"]","" ]
    }
    kv {
        source => "data"
        field_split => ","
        value_split => ":"
        trim_key => "[\{]"
        trim_value => "[\}]"
        prefix => "audit_"
    }
    #Thu Jun 18 08:01:42 +0200 2020
    if ("CEST" in [log_timestamp]) {
        mutate {gsub => ["log_timestamp", "CEST", "+0200"]}
        date {
            match => ["log_imestamp" , "E MMM dd HH:mm:ss Z yyyy"]
            #remove_field => ["log_timestamp"]
        }
    }
    if ("CET" in [log_timestamp]) {
        mutate {gsub => ["log_timestamp", "CET", "+0100"]}
        date {
            match => ["log_timestamp" , "E MMM dd HH:mm:ss Z yyyy"]
            #remove_field => ["log_timestamp"]
        }
    }
    date {
        match => ["log_timestamp" , "E MMM dd HH:mm:ss yyyy"]
        #remove_field => ["log_timestamp"]
    }

}

```

This is the output with the dateparsefailure for log\_timestamp. Could you please advise what I am doing wrong here?:

```
{
       "audit_caller" => "test.customer@customer1",
         "@timestamp" => 2020-06-18T18:51:54.716Z,
               "host" => "test@example.com",
            "message" => "Thu Jun 18 08:01:42 CEST 2020|{\"timestamp\":1592460102635,\"caller\":\"test.customer@customer1\",\"action\":\"LOGIN\",\"message\":\"ID000066 User [test.customer@customer1] logged in successfully.\"}",
               "data" => "{timestamp:1592460102635,caller:test.customer@customer1,action:LOGIN,message:ID000066 User [test.customer@customer1] logged in successfully.}",
      "audit_message" => "ID000066 User [test.customer@customer1] logged in successfully.",
           "@version" => "1",
    "audit_timestamp" => "1592460102635",
      "log_timestamp" => "Thu Jun 18 08:01:42 +0200 2020",
       "audit_action" => "LOGIN",
               "tags" => [
        [0] "_dateparsefailure"
    ]
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 18, 2020, 8:47pm UTC](https://discuss.elastic.co/t/dateparse-failure-using-the-date-filter/237692/2 "2020-06-18T20:47:20Z")

</div>

> [@marco2005](#):
>
> `match => ["log_timestamp" , "E MMM dd HH:mm:ss yyyy"]`

You need the Z for the timezone if you data looks like

```
"log_timestamp" => "Thu Jun 18 08:01:42 +0200 2020",

```

---

<div class="post-metadata">

**Author:** ![marco2005](https://avatars.discourse-cdn.com/v4/letter/m/b5ac83/32.png) [@marco2005](https://discuss.elastic.co/u/marco2005)\
**Post date:** [June 19, 2020, 9:34am UTC](https://discuss.elastic.co/t/dateparse-failure-using-the-date-filter/237692/3 "2020-06-19T09:34:22Z")

</div>

Thanks a lot.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 17, 2020, 9:34am UTC](https://discuss.elastic.co/t/dateparse-failure-using-the-date-filter/237692/4 "2020-07-17T09:34:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
