# Datetime parsing errors when including locale de-AT

**URL:** <https://discuss.elastic.co/t/datetime-parsing-errors-when-including-locale-de-at/268091>\
**Category:** Logstash\
**Created:** [March 23, 2021, 12:21pm UTC](https://discuss.elastic.co/t/datetime-parsing-errors-when-including-locale-de-at/268091 "2021-03-23T12:21:12Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![philippkahr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philippkahr/32/100137_2.png) [@philippkahr](https://discuss.elastic.co/u/philippkahr)\
**Post date:** [March 23, 2021, 12:21pm UTC](https://discuss.elastic.co/t/datetime-parsing-errors-when-including-locale-de-at/268091/1 "2021-03-23T12:21:13Z")

</div>

Hi,

I am at a loss, we have to deal with german encodings of month such as Dezember instead of December, or März instead of March, which also impacts the MMM notation instead of Mar it is Mär. This is an example message:

`23 Mär 2021 08:28:08,789 INFO additional log message`

This is my custom grok pattern for the datetime `JBOSSSERVERLOG %{MONTHDAY} %{MONTH} %{YEAR} %{TIME}`

This is my logstash config:

```auto

input {
  file {
    path => "/Users/philipp/Downloads/logstash/log/demolog.log"
  }
}

filter {
    grok {
      patterns_dir => ["/Users/philipp/Downloads/logstash/pipeline/custompattern"]
      match => [
        "message","%{JBOSSSERVERLOG:timestamp} %{LOGLEVEL:log.level} %{GREEDYDATA:message}"
        ]
      add_field => ["received_at", "%{@timestamp}"]
    }
    if [timestamp] =~ /(?:Jan(?:uary)?|Feb(?:ruary)?|Mar(?:ch)?|Apr(?:il)?|May|June?|July?|Aug(?:ust)?|Sep(?:tember)?|Oct(?:ober)?|Nov(?:ember)?|Dec(?:ember)?)/ {
      date {
        tag_on_failure => ["english-datetime-error"]
        match => [
          "timestamp",
          "dd MMM yyyy HH:mm:ss,SSS",
          "MMM dd, yyyy h:mm:ss a",
          "MMM dd, yyyy hh:mm:ss a",
          "MMM dd, yyyy hh:mm:ss,SSS a",
		      "dd/MMM/yyyy:HH:mm:ss Z"
          ]
      }
    }else{
      date {
        locale => "de-AT"
        tag_on_failure => ["german-datetime-error"]
        match => [
          "timestamp",
          "dd MMM yyyy HH:mm:ss,SSS"
          ]
      }
    }
}

output {
    stdout{
      codec => json 
      }
}

```

However it always ends up in something like this

```json
{
  "@timestamp": "2021-03-23T12:15:14.993Z",
  "host": "TAG-499.local",
  "log.level": "INFO",
  "path": "/Users/philipp/Downloads/logstash/log/demolog.log",
  "message": [
    "23 Mär 2021 08:28:08,789 INFO additional log message",
    "additional log message"
  ],
  "timestamp": "23 Mär 2021 08:28:08,789",
  "tags": ["german-datetime-error"],
  "@version": "1",
  "received_at": "2021-03-23T12:15:14.993Z"
}

```

Which makes no sense, since the `date` filter from logstash should match my own created timestamp field `dd MMM yyyy HH:mm:ss,SSS`.

I tried using `de`,`de-AT`,`de-DE` as locale but none of them worked. If I remove the tag on failure I get the default error with `_dateparsefailure`.

Here is a gist of running logstash with the `--debug` option. [logstash datetime errors · GitHub](https://gist.github.com/philippkahr/f806f845f2fe2e30755523fa4de7b616)

Any idea where I am going wrong?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2021, 12:21pm UTC](https://discuss.elastic.co/t/datetime-parsing-errors-when-including-locale-de-at/268091/2 "2021-04-20T12:21:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
