# \_dateparseerror for timestamp in this format: 2023-01-11T05:07:30.648881Z,

**URL:** <https://discuss.elastic.co/t/dateparseerror-for-timestamp-in-this-format-2023-01-11t0530-648881z/322959>\
**Category:** Logstash\
**Created:** [January 11, 2023, 5:04pm UTC](https://discuss.elastic.co/t/dateparseerror-for-timestamp-in-this-format-2023-01-11t0530-648881z/322959 "2023-01-11T17:04:36Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![rickfish](https://avatars.discourse-cdn.com/v4/letter/r/e480ec/32.png) [@rickfish](https://discuss.elastic.co/u/rickfish)\
**Post date:** [January 11, 2023, 5:04pm UTC](https://discuss.elastic.co/t/dateparseerror-for-timestamp-in-this-format-2023-01-11t0530-648881z/322959/1 "2023-01-11T17:04:36Z")

</div>

I am trying to parse a field called create\_ts with a value of 2023-01-11T05:07:30.648881Z and then add fields for year, month and day.

I have scoured everything to figure out the correct timestamp pattern and cannot seem to make it work.

I am using this filter:

```auto
filter {
   date { match => ["create_ts", "YYYY-MM-dd'T'HH:mm:ss.SSSSSSZ"]
        add_field => {"year" => "%{+YYYY}" }
        add_field => {"month" => "%{+MM}" }
        add_field => {"day" => "%{+dd}" }
   }
}

```

but I get a \_dateparseerror. I am sure I am doing something stupid but I am not sure what.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 11, 2023, 5:09pm UTC](https://discuss.elastic.co/t/dateparseerror-for-timestamp-in-this-format-2023-01-11t0530-648881z/322959/2 "2023-01-11T17:09:12Z")

</div>

Please, share the full log error you are getting and a sample document.

---

<div class="post-metadata">

**Author:** ![rickfish](https://avatars.discourse-cdn.com/v4/letter/r/e480ec/32.png) [@rickfish](https://discuss.elastic.co/u/rickfish)\
**Post date:** [January 11, 2023, 5:22pm UTC](https://discuss.elastic.co/t/dateparseerror-for-timestamp-in-this-format-2023-01-11t0530-648881z/322959/3 "2023-01-11T17:22:12Z")

</div>

This is a sample document:  
`{"create_yyyymm":202301,"create_ts":"2023-01-09T05:13:21.411713Z","create_user_i":"EMTREDIP"}`

This is the what I get from my stdout plugin:

```auto
{
       "@timestamp" => 2023-01-11T16:59:27.379431900Z,
         "@version" => "1",
    "create_yyyymm" => 202301,
        "create_ts" => 2023-01-09T05:13:21.411713Z,
             "tags" => [
        [0] "_dateparsefailure"
    ],
    "create_user_i" => "EMTREDIP"
}

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 11, 2023, 6:18pm UTC](https://discuss.elastic.co/t/dateparseerror-for-timestamp-in-this-format-2023-01-11t0530-648881z/322959/5 "2023-01-11T18:18:28Z")

</div>

I can covert with your data& code on v8.5.3 without any problem.  
Try:

```auto
   date { match => ["create_ts", "ISO8601"]
        add_field => {"year" => "%{+YYYY}" 
		"month" => "%{+MM}" 
		"day" => "%{+dd}" }
   }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 11, 2023, 6:49pm UTC](https://discuss.elastic.co/t/dateparseerror-for-timestamp-in-this-format-2023-01-11t0530-648881z/322959/6 "2023-01-11T18:49:51Z")

</div>

> [@rickfish](#):
>
> ```auto
> "create_ts" => 2023-01-09T05:13:21.411713Z,
> 
> ```

create\_ts is not a string, it is a LogStash::Timestamp (there are no double quotes around the value). A date filter [cannot parse that](https://github.com/logstash-plugins/logstash-filter-date/issues/95). Use mutate+convert to make it a string before the date filter.

---

<div class="post-metadata">

**Author:** ![rickfish](https://avatars.discourse-cdn.com/v4/letter/r/e480ec/32.png) [@rickfish](https://discuss.elastic.co/u/rickfish)\
**Post date:** [January 11, 2023, 7:23pm UTC](https://discuss.elastic.co/t/dateparseerror-for-timestamp-in-this-format-2023-01-11t0530-648881z/322959/7 "2023-01-11T19:23:40Z")

</div>

Thanks @Rios! It works with ISO8601.

---

<div class="post-metadata">

**Author:** ![rickfish](https://avatars.discourse-cdn.com/v4/letter/r/e480ec/32.png) [@rickfish](https://discuss.elastic.co/u/rickfish)\
**Post date:** [January 11, 2023, 7:24pm UTC](https://discuss.elastic.co/t/dateparseerror-for-timestamp-in-this-format-2023-01-11t0530-648881z/322959/8 "2023-01-11T19:24:40Z")

</div>

@Badger , the JSON is created by the jdbc input plugin so I am not actually creating it. So the jdbc input plugin creates the create\_ts value as a string. But I do see that it looks like logstash changed it to a non-string timestamp. I am a little confused. Changing the timestamp pattern from what I had to ISO8601 made it work though without doing a mutate+convert. Being pretty much a logstash newbie I am not sure why.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 11, 2023, 7:45pm UTC](https://discuss.elastic.co/t/dateparseerror-for-timestamp-in-this-format-2023-01-11t0530-648881z/322959/9 "2023-01-11T19:45:57Z")

</div>

Badger, I think you have good point here. Might be sometimes `create_ts` come as string and sometimes like date type. If this is import from Excel or csv then is possible.

@rickfish check types in Elasticsearch which are with tag \_dateparseerror, filter in Kibana.  
Btway, your `date { match => ["create_ts", "YYYY-MM-dd'T'HH:mm:ss.SSSSSSZ"]` is working fine on mine side for "create\_ts":"2023-01-09T05:13:21.411713Z". There is no explicitly mentioned which type should be 1st field, assume it's the string type.

#### `match`

- Value type is [array](https://www.elastic.co/guide/en/logstash/current/configuration-file-structure.html#array)
- Default value is `[]`

An array with field name first, and format patterns following, `[field, formats...]`

---

<div class="post-metadata">

**Author:** ![rickfish](https://avatars.discourse-cdn.com/v4/letter/r/e480ec/32.png) [@rickfish](https://discuss.elastic.co/u/rickfish)\
**Post date:** [January 11, 2023, 8:01pm UTC](https://discuss.elastic.co/t/dateparseerror-for-timestamp-in-this-format-2023-01-11t0530-648881z/322959/10 "2023-01-11T20:01:52Z")

</div>

@Rios, @Badger, long story. I guess the jdbc input plugin does create a timestamp column value as a timestamp in the json, not a string as I thought. I thought it was a string because the json created in my s3 output plugin converted the timestamp to a string. Since I couldn't see what was created by the jdbc input plugin, I assumed it looked exactly like what was put into the s3 file since I had no filter, just input and output.

Anyway, in order to test it without the jdbc and s3 plugins, I created a file with the line from the s3 file and used a file input plugin to test. But at the same time I changed my date pattern to ISO8601. My test worked so I thought it was the pattern.

When I switched back to the jdbc input, it failed again.

So I added the mutate/convert filter as suggested by @Badger and it now works like a champ.

Sorry for the long explanation, especially if it is convoluted.

Thanks again so much for the help.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 11, 2023, 8:13pm UTC](https://discuss.elastic.co/t/dateparseerror-for-timestamp-in-this-format-2023-01-11t0530-648881z/322959/11 "2023-01-11T20:13:46Z")

</div>

> [@rickfish](#):
>
> Sorry for the long explanation, especially if it is convoluted.

It's not long, actually is useful when you have feedback for a suggestion.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 11, 2023, 8:54pm UTC](https://discuss.elastic.co/t/dateparseerror-for-timestamp-in-this-format-2023-01-11t0530-648881z/322959/12 "2023-01-11T20:54:45Z")

</div>

> [@rickfish](#):
>
> I guess the jdbc input plugin does create a timestamp column value as a timestamp in the json

Yes, it does.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 8, 2023, 8:55pm UTC](https://discuss.elastic.co/t/dateparseerror-for-timestamp-in-this-format-2023-01-11t0530-648881z/322959/13 "2023-02-08T20:55:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
