# Extract datatime in log and convert in datatime field?

**URL:** <https://discuss.elastic.co/t/extract-datatime-in-log-and-convert-in-datatime-field/317021>\
**Category:** Logstash\
**Created:** [October 19, 2022, 3:14pm UTC](https://discuss.elastic.co/t/extract-datatime-in-log-and-convert-in-datatime-field/317021 "2022-10-19T15:14:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nikolas1306](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikolas1306/32/111507_2.png) [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Post date:** [October 19, 2022, 3:14pm UTC](https://discuss.elastic.co/t/extract-datatime-in-log-and-convert-in-datatime-field/317021/1 "2022-10-19T15:14:39Z")

</div>

i ve this config in logstash

```auto
filter
{

grok {
   match => ["message", "%{TIMESTAMP_ISO8601:timestamp_message}"]
}

  date {
           match => ["timestamp_message","YYYY-MM-dd HH:mm:ss"]
           target => "@timestamp"
      } 
}

```

but in my kibana "timestamp\_message" is not datetime filelds and is not have order

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/e/beb9abe61009e3337bc26c0e0e6591e228cb8722.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 19, 2022, 9:57pm UTC](https://discuss.elastic.co/t/extract-datatime-in-log-and-convert-in-datatime-field/317021/2 "2022-10-19T21:57:21Z")

</div>

Your [timestamp\_message] field has milliseconds. Your date filter has to consume that. Try `"YYYY-MM-dd HH:mm:ss,SSS"`.

---

<div class="post-metadata">

**Author:** ![Nikolas1306](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikolas1306/32/111507_2.png) [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Post date:** [October 19, 2022, 11:06pm UTC](https://discuss.elastic.co/t/extract-datatime-in-log-and-convert-in-datatime-field/317021/3 "2022-10-19T23:06:32Z")

</div>

hello i've resolved with

```auto

grok {
   match => ["message", "%{TIMESTAMP_ISO8601:logmessage}"]
 }

           
           date {
	         match => ["logmessage", "ISO8601", "YYYY-MM-dd HH:mm:ss"]
	         target => "logdate"
	        
        }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 16, 2022, 11:07pm UTC](https://discuss.elastic.co/t/extract-datatime-in-log-and-convert-in-datatime-field/317021/4 "2022-11-16T23:07:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
