# Error to set custom date pattern and change value of @timestamp

**URL:** <https://discuss.elastic.co/t/error-to-set-custom-date-pattern-and-change-value-of-timestamp/275170>\
**Category:** Logstash\
**Created:** [June 7, 2021, 2:52pm UTC](https://discuss.elastic.co/t/error-to-set-custom-date-pattern-and-change-value-of-timestamp/275170 "2021-06-07T14:52:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mar-ro](https://avatars.discourse-cdn.com/v4/letter/m/90ced4/32.png) [@mar-ro](https://discuss.elastic.co/u/mar-ro)\
**Post date:** [June 7, 2021, 2:52pm UTC](https://discuss.elastic.co/t/error-to-set-custom-date-pattern-and-change-value-of-timestamp/275170/1 "2021-06-07T14:52:07Z")

</div>

Hello!  
I've tried to use the following code to change the value of @timestamp but I couldn't do it..

```auto
input {
   pipeline { address => crontab }
}

filter {
   grok {
    match => { "message" => "(?<fecha>%{MONTH} %{MONTHNUM} %{HOUR}:%{MINUTE}:%{SECOND})"}
    tag_on_failure => ["no_date_found"]
    target => "fecha"
   }
   date {
     match => ["fecha", "MMM d HH:mm:ss"]
     target => "@timestamp"
     tag_on_failure => ["_dateparsefailure"]
   }

   mutate {
      add_field => { "[custom_index_name]" => "filebeat-logstash-%{[fields][name]}-%{+YYYY.MM.dd}" }
   }
}

output {
  pipeline { send_to => elasticsearch }
}

```

The date in the `message`field is the following:  
`Jun 7 14:14:01`

How should I set up the configuration file to get the correct value of date and put it in @timestamp field?  
Thank you!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 7, 2021, 4:44pm UTC](https://discuss.elastic.co/t/error-to-set-custom-date-pattern-and-change-value-of-timestamp/275170/2 "2021-06-07T16:44:54Z")

</div>

> [@mar-ro](#):
>
> ```
> `"MMM d HH:mm:ss"`
> 
> ```

That has two spaces between MMM and d, but your example data only has one.

---

<div class="post-metadata">

**Author:** ![mar-ro](https://avatars.discourse-cdn.com/v4/letter/m/90ced4/32.png) [@mar-ro](https://discuss.elastic.co/u/mar-ro)\
**Post date:** [June 8, 2021, 7:31am UTC](https://discuss.elastic.co/t/error-to-set-custom-date-pattern-and-change-value-of-timestamp/275170/3 "2021-06-08T07:31:43Z")

</div>

It's true @Badger , but after change that, the error continues... Do you know why? Thank you !

---

<div class="post-metadata">

**Author:** ![angelo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/angelo/32/61325_2.png) [@angelo](https://discuss.elastic.co/u/angelo)\
**Post date:** [June 8, 2021, 7:52pm UTC](https://discuss.elastic.co/t/error-to-set-custom-date-pattern-and-change-value-of-timestamp/275170/4 "2021-06-08T19:52:11Z")

</div>

You also have a `target` specified as part of your grok ... this will result in any grok'ed fields being sub-fields to the specified top-level field called `fecha` - ie: your extracted date field will actually be in `fecha.fecha`. You should remove the `target` in the grok or if you need it, then to access the date field, your date match syntax needs to be the following - as well as taking @Badger's comment into consideration or use the recommended pattern in LS [docs](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html):

```auto
match => ["[fecha][fecha]", "MMM dd HH:mm:ss"]`.

```

You can also simplify your grok match to leverage the built-in syslog time format:

```auto
match => {"message" => "%{SYSLOGTIMESTAMP:fecha}"}`

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2021, 7:52pm UTC](https://discuss.elastic.co/t/error-to-set-custom-date-pattern-and-change-value-of-timestamp/275170/5 "2021-07-06T19:52:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
