# Dateparsefailure on time field

**URL:** <https://discuss.elastic.co/t/dateparsefailure-on-time-field/247927>\
**Category:** Logstash\
**Created:** [September 8, 2020, 8:48pm UTC](https://discuss.elastic.co/t/dateparsefailure-on-time-field/247927 "2020-09-08T20:48:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ankitachow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitachow/32/46246_2.png) [@ankitachow](https://discuss.elastic.co/u/ankitachow)\
**Post date:** [September 8, 2020, 8:48pm UTC](https://discuss.elastic.co/t/dateparsefailure-on-time-field/247927/1 "2020-09-08T20:48:37Z")

</div>

I have date and time as separate fields in my input file. Date as 2019-08-28 ("yyyy-MM-dd"). Time as 09:33:05.579476547 (HH:mm:ss.SSSSSSSSZ). I want to merge the date and time for every record and create a timestamp field which will be the @timestamp for the ES index to be indexed upon.

I use below mutate but getting a dateparsefailure.

```
  mutate {
     remove_field => ["message"]
     rename => { "[dest][date]" => "new_date" }
     remove_field => "[dest][date]"
     rename => { "[dest][time]" => "new_time" }
     remove_field => "[dest][time]"
     add_field => {
         "timestamp" => "%{new_date} %{new_time}"
     }
  }
  date {
    match => ["timestamp" , "yyyy-MM-dd'T'HH:mm:ss.SSSSSSZ"]
  }
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 8, 2020, 8:54pm UTC](https://discuss.elastic.co/t/dateparsefailure-on-time-field/247927/2 "2020-09-08T20:54:04Z")

</div>

Z matches a timezone, which your field does not have, and it has 9 digits subsecond, and you have a space separating date and time. Try

```
"yyyy-MM-dd HH:mm:ss.SSSSSSSSS"
```

---

<div class="post-metadata">

**Author:** ![ankitachow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitachow/32/46246_2.png) [@ankitachow](https://discuss.elastic.co/u/ankitachow)\
**Post date:** [September 8, 2020, 9:16pm UTC](https://discuss.elastic.co/t/dateparsefailure-on-time-field/247927/3 "2020-09-08T21:16:19Z")

</div>

It worked.

How can I format the ts to "yyyy-MM-dd'T'HH:mm:ss.SSSSSSZ" format?

Also, I would like to keep both ts, that is @timestamp & new\_timestamp which is created from file. But when I use below mutate, I can see both the fields having value from file.

```
  mutate {
     remove_field => ["message"]
     rename => { "[dest][date]" => "new_date" }
     remove_field => "[dest][date]"
     rename => { "[dest][time]" => "new_time" }
     remove_field => "[dest][time]"
     add_field => {
         "new_timestamp" => "%{new_date} %{new_time}"
     }
  }
  date {
    match => ["new_timestamp" , "yyyy-MM-dd HH:mm:ss.SSSSSSSSS"]
  }

```

stdout:

```
{
       "@timestamp" => 2019-08-28T14:33:05.638Z,
    "new_timestamp" => "2019-08-28 09:33:05.638065493",
         "new_date" => "2019-08-28",
         "new_time" => "09:33:05.638065493"
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 8, 2020, 11:03pm UTC](https://discuss.elastic.co/t/dateparsefailure-on-time-field/247927/4 "2020-09-08T23:03:23Z")

</div>

> [@ankitachow](#):
>
> How can I format the ts to "yyyy-MM-dd'T'HH:mm:ss.SSSSSSZ" format?

I do not understand the question.

Use the target option for the date filter to overwrite new\_timestamp

```
target => "new_timestamp"

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 6, 2020, 11:03pm UTC](https://discuss.elastic.co/t/dateparsefailure-on-time-field/247927/5 "2020-10-06T23:03:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
