# Error in Logstash - failed to parse date field with format strict\_date\_optional\_time||epoch\_millis date-time-parse-exception

**URL:** <https://discuss.elastic.co/t/error-in-logstash-failed-to-parse-date-field-with-format-strict-date-optional-time-epoch-millis-date-time-parse-exception/329797>\
**Category:** Logstash\
**Created:** [April 12, 2023, 5:49am UTC](https://discuss.elastic.co/t/error-in-logstash-failed-to-parse-date-field-with-format-strict-date-optional-time-epoch-millis-date-time-parse-exception/329797 "2023-04-12T05:49:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sarath.sarepaka](https://avatars.discourse-cdn.com/v4/letter/s/dc4da7/32.png) [@sarath.sarepaka](https://discuss.elastic.co/u/sarath.sarepaka)\
**Post date:** [April 12, 2023, 5:49am UTC](https://discuss.elastic.co/t/error-in-logstash-failed-to-parse-date-field-with-format-strict-date-optional-time-epoch-millis-date-time-parse-exception/329797/1 "2023-04-12T05:49:36Z")

</div>

Hi,

We are getting the below error in the logstash. We are using a field called "destination" for both time and string. We observed below issue when the destination field value is a string .

ELasticsearch and Logstash versions are 7.16.3

Error:

"reason"=\>"failed to parse field [destination] of type [date] in document with id '\*\*\*\*\*'. Preview of field's value: 'REDIS'", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"failed to parse date field [REDIS] with format [strict\_date\_optional\_time||epoch\_millis]", "caused\_by"=\>{"type"=\>"date\_time\_parse\_exception", "reason"=\>"date\_time\_parse\_exception: Failed to parse with all enclosed parsers"}}}}}}

Below is our Logstash configuration:

```auto
else if [sourceType] == "filebeat" {
       json {
            source => "message"
            target => "parsedJson"
        }
    mutate {
        remove_field => [
            "[message]"
        ]
        lowercase => ["app"]
    }

    if (![latency] or [latency]=="") {
        mutate {
            add_field => {
                latency => -1
            }
        }
    }
    mutate {
        convert => {
            "latency" => "integer"
        }
    }

        date {
        match => ["ts", "yyyy-MM-dd HH:mm:ss,SSS"]
        timezone => "Europe/London"
        target => ["df_ts"]
        remove_field => ["ts"]
    }
	
	mutate {
	   convert => {
	      "destination" => "string"
    }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 12, 2023, 3:35pm UTC](https://discuss.elastic.co/t/error-in-logstash-failed-to-parse-date-field-with-format-strict-date-optional-time-epoch-millis-date-time-parse-exception/329797/2 "2023-04-12T15:35:30Z")

</div>

> [@sarath.sarepaka](#):
>
> We are using a field called "destination" for both time and string.

That is what causes the problem. A field in elasticsearch can only have one type (i.e. date _or_ string). In the default configuration, [date detection](https://www.elastic.co/guide/en/elasticsearch/reference/current/dynamic-field-mapping.html#date-detection) will set the field type to date if it sees something that appears to be epoch\_millis. Any events that try to set it to string after that will get the error you are seeing.

You could fix this by adding an [index template](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html) that forces the field to be mapped as a string.

---

<div class="post-metadata">

**Author:** ![sarath.sarepaka](https://avatars.discourse-cdn.com/v4/letter/s/dc4da7/32.png) [@sarath.sarepaka](https://discuss.elastic.co/u/sarath.sarepaka)\
**Post date:** [April 13, 2023, 4:58am UTC](https://discuss.elastic.co/t/error-in-logstash-failed-to-parse-date-field-with-format-strict-date-optional-time-epoch-millis-date-time-parse-exception/329797/3 "2023-04-13T04:58:35Z")

</div>

Can you please share on how to dynamically map the field type. At the start of the day , if the destination type is date, then we are facing this issue because it is trying to parse the destination field value from REDIS to date and erroring out as below

Could not index event to Elasticsearch. Failed to parse field [destination] of type [date] in document. Preview of field's value: 'REDIS'", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"failed to parse date field [REDIS] with format [strict\_date\_optional\_time||epoch\_millis]", "caused\_by"=\>{"type"=\>"date\_time\_parse\_exception", "reason"=\>"date\_time\_parse\_exception: Failed to parse with all enclosed parsers.

PLease share us your suggestions on how to forcibly map the field to be string ? Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 13, 2023, 12:30pm UTC](https://discuss.elastic.co/t/error-in-logstash-failed-to-parse-date-field-with-format-strict-date-optional-time-epoch-millis-date-time-parse-exception/329797/4 "2023-04-13T12:30:34Z")

</div>

You can use an index template to force the mapping to be string.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2023, 12:30pm UTC](https://discuss.elastic.co/t/error-in-logstash-failed-to-parse-date-field-with-format-strict-date-optional-time-epoch-millis-date-time-parse-exception/329797/5 "2023-05-11T12:30:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
