# Dateparsefailure on conversion

**URL:** <https://discuss.elastic.co/t/dateparsefailure-on-conversion/135592>\
**Category:** Logstash\
**Created:** [June 12, 2018, 7:42pm UTC](https://discuss.elastic.co/t/dateparsefailure-on-conversion/135592 "2018-06-12T19:42:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![pjanzen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pjanzen/32/13756_2.png) [@pjanzen](https://discuss.elastic.co/u/pjanzen)\
**Post date:** [June 12, 2018, 7:42pm UTC](https://discuss.elastic.co/t/dateparsefailure-on-conversion/135592/1 "2018-06-12T19:42:47Z")

</div>

Hi All.

I have the following timestamp 20180612 21:07:10.197 and I am using the this match:

```
date {
      # 2018-06-04T07:25:13.943Z
      # 20180605 16:37:34.966
      match => ['ts', 'yyyymmdd hh:mm:ss.SSS']
      timezone => "CET"
      target => "@timestamp"
    }

```

I do however end up with a \_dateparsefailure

An example logline is this:

> 20180610 16:49:02.647 core id=x2p11x00736y3Au012p1mC wf=smtp::6:39 msg="logid=data\_accept\_default ip=62.144.109.144 [revdns=mx109e144.fagms.de](http://revdns=mx109e144.fagms.de) canrelay=?? action=P6\_ACCEPT\_DEFAULT"

and the logstash part I use to decompose this line is as follows:

```
if [message] =~ /action=P/ {
    dissect {
      mapping => {
        "message" => "%{ts} %{+ts} %{message}"
      }
    }
    kv {
      source => "message"
        prefix => "imp_"
      }
    }
}

```

produces the following output:

```
   {
  "_index": "clog-2018.06.12",
  "_type": "doc",
  "_id": "jBZz9WMBP1gu3W4L3uma",
  "_version": 1,
  "_score": null,
  "_source": {
    "offset": 1985746470,
    "message": "core id=x2p11x00736y3Au012p1mC wf=smtp::6:39 msg=logid=data_accept_default ip=62.144.109.144 revdns=mx109e144.fagms.de canrelay=?? action=P6_ACCEPT_DEFAULT",
    "beat": {
      "version": "6.2.4",
      "hostname": "mx7.12345.net",
      "name": "mx7.12345.net"
    },
    "imp_wf": "smtp::6:39",
    "ts": "20180610 16:49:02.647",
    "imp_msg": "logid=data_accept_default",
    "imp_ip": "62.144.109.144",
    "@version": "1",
    "imp_action": "P6_ACCEPT_DEFAULT",
    "imp_revdns": "mx109e144.fagms.de",
    "source": "/var/log/bizimp/filters.log",
    "source_affiliate": "ukmail",
    "host": "mx7.12345.net",
    "@timestamp": "2018-06-12T19:22:47.311Z",
    "tags": [
      "CM",
      "beats_input_codec_plain_applied",
      "_dateparsefailure"
    ],
    "imp_id": "x2p11x00736y3Au012p1mC",
    "prospector": {
      "type": "log"
    },
    "imp_canrelay": "??",
    "geoip": {
      "continent_code": "EU",
      "country_code3": "DE",
      "location": {
        "lat": 51.2993,
        "lon": 9.491
      },
      "country_code2": "DE",
      "country_name": "Germany",
      "longitude": 9.491,
      "ip": "62.144.109.144",
      "latitude": 51.2993
    }
  },
  "fields": {
    "@timestamp": [
      "2018-06-12T19:22:47.311Z"
    ]
  },
"highlight": {
    "imp_action": [
      "@kibana-highlighted-field@P6_ACCEPT_DEFAULT@/kibana-highlighted-field@"
    ]
  },
  "sort": [
    1528831367311
  ]
}

```

I do not understand why this is happening...

---

<div class="post-metadata">

**Author:** ![CDR](https://avatars.discourse-cdn.com/v4/letter/c/d9b06d/32.png) [@CDR](https://discuss.elastic.co/u/CDR)\
**Post date:** [June 12, 2018, 7:52pm UTC](https://discuss.elastic.co/t/dateparsefailure-on-conversion/135592/2 "2018-06-12T19:52:50Z")

</div>

Try replacing the lowercase mm in yyyy **mm** dd to yyyy **MM** dd. Same thing with the hh for hours. Replace the lowercase hh's to HH.

See this link about dates:  
[https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html)

I think that Logstash may be trying to parse the month as minutes since you are using lowercase m's. If that isn't the correct problem you should still probably fix it.

---

<div class="post-metadata">

**Author:** ![pjanzen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pjanzen/32/13756_2.png) [@pjanzen](https://discuss.elastic.co/u/pjanzen)\
**Post date:** [June 12, 2018, 7:56pm UTC](https://discuss.elastic.co/t/dateparsefailure-on-conversion/135592/3 "2018-06-12T19:56:55Z")

</div>

Thanks, that did the trick...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2018, 7:57pm UTC](https://discuss.elastic.co/t/dateparsefailure-on-conversion/135592/4 "2018-07-10T19:57:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
