# Failed parsing date from field Oracle alert log

**URL:** <https://discuss.elastic.co/t/failed-parsing-date-from-field-oracle-alert-log/351590>\
**Category:** Logstash\
**Created:** [January 23, 2024, 4:49am UTC](https://discuss.elastic.co/t/failed-parsing-date-from-field-oracle-alert-log/351590 "2024-01-23T04:49:35Z")\
**Posts on this page:** 1\
**Showing post:** 11

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [January 23, 2024, 5:51pm UTC](https://discuss.elastic.co/t/failed-parsing-date-from-field-oracle-alert-log/351590/11 "2024-01-23T17:51:53Z")

</div>

> [@Prabhu\_Athithan](#):
>
> mem# 0: /u01/app/oracle/oradata/ORCLDR/redo03.log\n2024-01-23T23:14:14.004318+05:30\nARC1 (PID:3224): Archived Log entry 86 added for T-1.S-101 ID 0x6484cf48 LAD:1",  
> "@version" =\> "1",  
> "@timestamp" =\> "2024-01-23T17:44:13.797Z",

This looks correct to me. Logstash has normalized your timestamp to UTC and will show the timestamp according to the user's browser's timezone. See: [How to set @timestamp timezone?](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401)

Example:  
Original: `2024-01-23T23:14:14.004318+05:30`  
UTC Time: `2024-01-23T17:44:14.004Z`  
Which matches what you're seeing.

Though it does look like we're saving these values to `timestamp` and not `@timestamp` you might want to change your date filter to:

```auto
date {
  locale => "en"
  match => ["timestamp","ISO8601"]
  target => "@timestamp"
}

```

Otherwise my guess is that you've got a `timestamp` field and a `@timestamp` field.

---

_[View the full topic](https://discuss.elastic.co/t/failed-parsing-date-from-field-oracle-alert-log/351590)._
