# Failed multiple date fields parsing

**URL:** <https://discuss.elastic.co/t/failed-multiple-date-fields-parsing/114101>\
**Category:** Logstash\
**Created:** [January 4, 2018, 1:50pm UTC](https://discuss.elastic.co/t/failed-multiple-date-fields-parsing/114101 "2018-01-04T13:50:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![cilzzz](https://avatars.discourse-cdn.com/v4/letter/c/c67d28/32.png) [@cilzzz](https://discuss.elastic.co/u/cilzzz)\
**Post date:** [January 4, 2018, 1:50pm UTC](https://discuss.elastic.co/t/failed-multiple-date-fields-parsing/114101/1 "2018-01-04T13:50:02Z")

</div>

Hi i have a logfile which contains mutiple date fields and i need to parse 3 date fields

in my logstash config file i've wrote :

```
date {
                  match => ["Starting_Time", "yy-MM-dd HH:mm:ss"]
                  timezone => "Europe/Paris"
                  target => "@timestamp"
              }

date {
                  match => ["start_rxdate", "yy-MM-dd"]
                  timezone => "Europe/Paris"
                  target => "start_rxdate"
      }

date {
                  match => ["start_rxtime", "HH:mm:ss"]
                  timezone => "Europe/Paris"
                  target => "start_rxtime"
      }

```

hte only date that worked is the one who has the @timestamp as a target

can someone help

thank you!

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [January 4, 2018, 2:52pm UTC](https://discuss.elastic.co/t/failed-multiple-date-fields-parsing/114101/2 "2018-01-04T14:52:14Z")

</div>

Why do you need to convert `start_rxdate` and `start_rxtime` to Time object instances?

They will be converted back to strings when serialising to ES - except they will have the missing component (time or date) added.  
e.g.  
if `start_rxdate` is "18-01-03", you get "2018-01-02T23:00:00.000Z" when serialized.  
if `start_rxtime` is "11:12:13" (today being the 4th of Jan), you get "2018-01-04T12:12:13.000Z" when serialized.

I think you want to join `start_rxdate` and `start_rxtime` to a new field called say `start_rxts` and then use the date filter on that.

---

<div class="post-metadata">

**Author:** ![cilzzz](https://avatars.discourse-cdn.com/v4/letter/c/c67d28/32.png) [@cilzzz](https://discuss.elastic.co/u/cilzzz)\
**Post date:** [January 5, 2018, 8:54am UTC](https://discuss.elastic.co/t/failed-multiple-date-fields-parsing/114101/3 "2018-01-05T08:54:09Z")

</div>

thank you actually it worked the way i did it it needed time to make the changes, i need the two field separated because i need to sketch on kibana start\_rxtime (y axis) and start\_rxdate (x axis)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 2, 2018, 8:54am UTC](https://discuss.elastic.co/t/failed-multiple-date-fields-parsing/114101/4 "2018-02-02T08:54:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
