# Dateparsefailure

**URL:** https://discuss.elastic.co/t/dateparsefailure/88592
**Category:** Logstash
**Created:** [June 7, 2017, 2:13pm UTC](https://discuss.elastic.co/t/dateparsefailure/88592 "2017-06-07T14:13:19Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![chimbo84](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@chimbo84](https://discuss.elastic.co/u/chimbo84)
#### Post date: [June 7, 2017, 2:13pm UTC](https://discuss.elastic.co/t/dateparsefailure/88592/1 "2017-06-07T14:13:19Z")

</div>

I have a log line that reads something like the following (there is a space between the date and time, not a new line):

> 2017-06-07 10:15:42.406424+00:00,CSLUR,3,###########,###########,0xffffffff,310,026,61002,R,15,U,H

My logstash filter reads as such:

> if ([message] =~ "CSLUR") {  
> csv {  
> columns =\> [  
> "date",  
> "event\_type",  
> "log\_ver",  
> "imsi",  
> "imei",  
> "tmsi",  
> "mcc",  
> "mnc",  
> "lac",  
> "acceptorreject",  
> "cause\_code",  
> "whitelist",  
> "guest"  
> ]  
> }  
> date {  
> match =\> ["date", "ISO8601", "yyyy-MM-dd HH:mm:ss.SSSZZ"]  
> }  
> }

I keep getting dateparsefailures and the @timestamp field is still read time, not message time. How do I debug the dateparsefailure?

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [June 7, 2017, 2:18pm UTC](https://discuss.elastic.co/t/dateparsefailure/88592/2 "2017-06-07T14:18:32Z")

</div>

I'm not sure SSS likes microseconds. You might have to use SSSSSS or remove the last three digits from the `date` field (ES only supports millisecond resolution anyway). The mutate filter's gsub option can be used to trim the superfluous digits.

---

<div class="post-metadata">

### Author: ![chimbo84](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@chimbo84](https://discuss.elastic.co/u/chimbo84)
#### Post date: [June 7, 2017, 2:46pm UTC](https://discuss.elastic.co/t/dateparsefailure/88592/3 "2017-06-07T14:46:11Z")

</div>

Thanks magnusbaeck. Changing it to "SSSSSS" worked.

I added a target date field and manually mapped it in ES to 'date' but should I need to do that (the mapping) in the future?

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [June 7, 2017, 6:17pm UTC](https://discuss.elastic.co/t/dateparsefailure/88592/4 "2017-06-07T18:17:00Z")

</div>

I think ES's automapper automatically does the right thing in this case.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 6:17pm UTC](https://discuss.elastic.co/t/dateparsefailure/88592/5 "2017-07-05T18:17:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
