# Error using date match filter

**URL:** <https://discuss.elastic.co/t/error-using-date-match-filter/45740>\
**Category:** Logstash\
**Created:** [March 29, 2016, 11:26pm UTC](https://discuss.elastic.co/t/error-using-date-match-filter/45740 "2016-03-29T23:26:11Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wolls013](https://avatars.discourse-cdn.com/v4/letter/w/bcef8e/32.png) [@Wolls013](https://discuss.elastic.co/u/Wolls013)\
**Post date:** [March 29, 2016, 11:26pm UTC](https://discuss.elastic.co/t/error-using-date-match-filter/45740/1 "2016-03-29T23:26:11Z")

</div>

Hi everyone,

I keep getting an error while trying to make my timestamp ("time") field from my MS SQL database the @timestamp field using the date match filter in logstash.

This is my input i'm using for my timestamp:  
2015-06-02 17:13:51.331 +00:00

This is my filter i'm using in my conf file

```
`filter {
     date {
  match => ["time","YYYY-MM-dd HH:mm:ss.SSS"]
  locale => "en"
  target => "@timestamp"
 }
}`

```

This filter produces the error:  
_Side note_: I get this error also using the match pattern  
match =\> ["time","YYYY-MM-dd HH:mm:ss Z"],  
match =\> ["time","YYYY-MM-dd HH:mm:ss"]

**Failed parsing date from field {:field=\>"time", :value=\>#Java::MicrosoftSql::DateTimeOffset:0xe9c298, :exception=\>"failed to coerce microsoft.sql.DateTimeOffset to java.lang.String", :config\_parsers=\>"YYYY-MM-dd HH:mm:ss.SSS", :config\_locale=\>"en", :level=\>:warn}**

I'm pretty new to logstash and the ELK stack in general and to me it appears to be an issue with the data type itself being exported by the MS SQL database but i'm not sure. If anyone knows what's going wrong here or has any ideas how to fix it I would love some help.

Thanks for any help!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 30, 2016, 2:02am UTC](https://discuss.elastic.co/t/error-using-date-match-filter/45740/2 "2016-03-30T02:02:39Z")

</div>

You should just be able to use `TIMESTAMP_ISO8601` as the pattern.

---

<div class="post-metadata">

**Author:** ![Suren92](https://avatars.discourse-cdn.com/v4/letter/s/f475e1/32.png) [@Suren92](https://discuss.elastic.co/u/Suren92)\
**Post date:** [March 30, 2016, 3:12am UTC](https://discuss.elastic.co/t/error-using-date-match-filter/45740/3 "2016-03-30T03:12:07Z")

</div>

Hi,

Are you using any kind of grok pattern to extract the data?

---

<div class="post-metadata">

**Author:** ![mick66](https://avatars.discourse-cdn.com/v4/letter/m/d2c977/32.png) [@mick66](https://discuss.elastic.co/u/mick66)\
**Post date:** [March 30, 2016, 1:26pm UTC](https://discuss.elastic.co/t/error-using-date-match-filter/45740/4 "2016-03-30T13:26:57Z")

</div>

I had this issue too and got around it by first converting the sql date field to a string, then running the date filter:

```
filter {
     mutate {
        convert => ["time", "string"]
     }
        
     date {
         match => ["time", ISO8601]
         target => "@timestamp"
     }

     mutate {
        remove_field => ["time"]
     }
}
```

---

<div class="post-metadata">

**Author:** ![joedissmeyer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joedissmeyer/32/26163_2.png) [@joedissmeyer](https://discuss.elastic.co/u/joedissmeyer)\
**Post date:** [March 24, 2017, 6:10pm UTC](https://discuss.elastic.co/t/error-using-date-match-filter/45740/5 "2017-03-24T18:10:15Z")

</div>

Thank you @mick66! This resolved the MSSQL time issue for me as well.

I'm using the JDBC driver to harvest time series data from a SolarWinds Orion database (pulling in triggered alerts) for dashboarding and analysis in Kibana. Your example of having to convert the SQL date field to a string first is EXACTLY what I needed to know for my solution. Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:27am UTC](https://discuss.elastic.co/t/error-using-date-match-filter/45740/6 "2017-07-06T04:27:35Z")

</div>


