# Failed to parse string date field

**URL:** <https://discuss.elastic.co/t/failed-to-parse-string-date-field/234235>\
**Category:** Logstash\
**Created:** [May 26, 2020, 3:54am UTC](https://discuss.elastic.co/t/failed-to-parse-string-date-field/234235 "2020-05-26T03:54:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![psteh](https://avatars.discourse-cdn.com/v4/letter/p/f05b48/32.png) [@psteh](https://discuss.elastic.co/u/psteh)\
**Post date:** [May 26, 2020, 3:54am UTC](https://discuss.elastic.co/t/failed-to-parse-string-date-field/234235/1 "2020-05-26T03:54:07Z")

</div>

Here is my logstash filter  
Given `created_at`, `updated_at`, `deleted_at` is string, I would like to convert these fields to `date`

Gotten error when trying to insert documents.

```auto
Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"cwl-2020.05.22", :_type=>"_doc", :routing=>nil}, #<LogStash::Event:0x7aac85db>], :response=>{"index"=>{"_index"=>"cwl-2020.05.22", "_type"=>"_doc", "_id"=>"cu8TT3IBY8xh4kUUqvAx", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [properties.old.updated_at] of type [date] in document with id 'cu8TT3IBY8xh4kUUqvAx'. Preview of field's value: '2020-05-21 16:02:17'", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"failed to parse date field [2020-05-21 16:02:17] with format [strict_date_optional_time||epoch_millis]", "caused_by"=>{"type"=>"date_time_parse_exception", "reason"=>"Failed to parse with all enclosed parsers"}}}}}}

```

What went wrong on my configuration?

Below is the sample document

```auto
"old" => {
                      "created_at" => "2020-05-20 17:43:25",
                       "deleted_at" => nil,
                               "id" => 49225,
                       "updated_at" => "2020-05-21 14:31:30",
                "status_updated_at" => nil
        }

```

Below is my part of `filter`

```auto
if [properties] {
		if [old] {
			if [created_at] {
				date {
					match => ["[properties][old][created_at]", "yyyy-MM-dd HH:mm:ss" ]
    				target => "[properties][old][created_at]"
				}
			}
			if [updated_at] {
				date {
					match => ["[properties][old][updated_at]", "yyyy-MM-dd HH:mm:ss" ]
    				target => "[properties][old][updated_at]"
				}
			}
			if [deleted_at] {
				date {
					match => ["[properties][old][deleted_at]", "yyyy-MM-dd HH:mm:ss" ]
    				target => "[properties][old][deleted_at]"
				}
			}
		}
	}

```

Below is mapping template

```auto
"old": {
	"properties": {
		"created_at": {
			"type": "date",
			"format": "yyyy-MM-dd HH:mm:ss"
		},
		"updated_at": {
			"type": "date",
			"format": "yyyy-MM-dd HH:mm:ss"
		},
		"deleted_at": {
			"type": "date",
			"format": "yyyy-MM-dd HH:mm:ss"
		}
	}
}

```

Thank you for your time.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 26, 2020, 4:19pm UTC](https://discuss.elastic.co/t/failed-to-parse-string-date-field/234235/2 "2020-05-26T16:19:27Z")

</div>

> [@psteh](#):
>
> "reason"=\>"failed to parse date field [2020-05-21 16:02:17] with format [strict\_date\_optional\_time||epoch\_millis]"

strict\_date\_optional\_time is a generic ISO datetime parser where the date, in `year_month_day` format, is mandatory and the time, separated by `T` , is optional.

I think the problem might be your if conditions. When you write

```
if [properties] {
    if [old] {
        if [created_at] {

```

you are testing whether all three fields exist at the top level. You may want

```
if [properties][old][created_at] {

```

If your date filter gets applied then I think logstash will send the date in a format that elasticsearch will accept.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 23, 2020, 4:19pm UTC](https://discuss.elastic.co/t/failed-to-parse-string-date-field/234235/3 "2020-06-23T16:19:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
