# Failed to parse \[timestamp\] invalid formate

**URL:** <https://discuss.elastic.co/t/failed-to-parse-timestamp-invalid-formate/52926>\
**Category:** Logstash\
**Created:** [June 15, 2016, 10:28pm UTC](https://discuss.elastic.co/t/failed-to-parse-timestamp-invalid-formate/52926 "2016-06-15T22:28:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Josh\_Reichardt](https://avatars.discourse-cdn.com/v4/letter/j/f08c70/32.png) [@Josh\_Reichardt](https://discuss.elastic.co/u/Josh_Reichardt)\
**Post date:** [June 15, 2016, 10:28pm UTC](https://discuss.elastic.co/t/failed-to-parse-timestamp-invalid-formate/52926/1 "2016-06-15T22:28:47Z")

</div>

I am attempting to parse some syslog messages and I'm seeing the following message in the Logstash logs whenever I try to match some parsed syslog field:

`:response=>{"create"=>{"_index"=>"logstash-2016.06.15", "_type"=>"logstash", "_id"=>"AVVWH4KY1Ye0QKQmJ6e1", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse [timestamp]", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"Invalid format: \"2016-06-15 22:12:33,254\" is malformed at \"-06-15 22:12:33,254\""}}}}, :level=>:warn}`

Here are the configs causing the problem:

```auto
if [type] == "logstash" {
    grok {
      match => ["message", "<%{POSINT:syslog_pri}>%{TIMESTAMP_ISO8601:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" ]
    }
    date {
      match => ["syslog_timestamp", "ISO8601"]
      remove_field => ["syslog_timestamp"]
    }
    mutate {
      lowercase => ["syslog_hostname"]
      add_field => { "environment" => "%{syslog_hostname}" }
      replace => { "message" => "%{syslog_message}" }
      remove_field => ["syslog_message"]
    }
  }

```

This part seems to be fine until I try to match a parsed field later in the filter. For example, like this:

```auto
if [syslog_program] =~ /nginx/ {
    grok {
      match => ["message", "%{IPORHOST:clientip} - - \[%{HTTPDATE:timestamp}\] %{QS:request} %{INT:status} %{INT:body_bytes_sent} %{QS:http_referer} %{QS:agent}" ]
      add_tag => ["nginx"]
    }
}

```

I'm not really sure what to make of the error and googling hasn't helped much. I'm wondering if there is some issue or conflict with my timestamp?

---

<div class="post-metadata">

**Author:** ![Josh\_Reichardt](https://avatars.discourse-cdn.com/v4/letter/j/f08c70/32.png) [@Josh\_Reichardt](https://discuss.elastic.co/u/Josh_Reichardt)\
**Post date:** [June 16, 2016, 12:48am UTC](https://discuss.elastic.co/t/failed-to-parse-timestamp-invalid-formate/52926/2 "2016-06-16T00:48:15Z")

</div>

I removed the `timestamp` from the grok pattern and it started working. Still not sure why that changes matters, if someone knows that would be great.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:52am UTC](https://discuss.elastic.co/t/failed-to-parse-timestamp-invalid-formate/52926/3 "2017-07-06T04:52:36Z")

</div>


