# Failed to parse Timestamp

**URL:** <https://discuss.elastic.co/t/failed-to-parse-timestamp/36920>\
**Category:** Logstash\
**Created:** [December 10, 2015, 9:06pm UTC](https://discuss.elastic.co/t/failed-to-parse-timestamp/36920 "2015-12-10T21:06:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sombilat](https://avatars.discourse-cdn.com/v4/letter/s/779978/32.png) [@sombilat](https://discuss.elastic.co/u/sombilat)\
**Post date:** [December 10, 2015, 9:06pm UTC](https://discuss.elastic.co/t/failed-to-parse-timestamp/36920/1 "2015-12-10T21:06:19Z")

</div>

Hello Guys,

need some help.  
In my logstash I am reading a date pattern from input files.  
I have defined a format in my mapping with dd/MM/yyyy HH:mm:ss.SSS, so when it reads the input files it would follow the format i defined in mapping.

Now older files have a different format, where in old files have no milisecond(SSS) included in them. Reading around the discussion, it is said that Logstash should automatically fill up the missing milisecondds. Yet they dont, instead logstash throws a mapper\_parsing\_exception. As seen in the image below:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/1bd29420addd357d1304d61685eea9f335243452.JPG)

I tried appending data when it encounters a dateparsefailure, like below:

> ```
> date {
> match => ["tslice", "dd/MM/yyyy HH:mm:ss "]    
> }
>  
> if ([tags] == "_dateparsefailure"){
> mutate {
> update => {"tslice" => "%{tslice}.000" }
> }
> }
> 
> ```

So when it encounters the date, it would append zeroes which would match the dateformat defined in my mapping.

How do I make it that it will accept the input with no milisecond, and replace it with zeroes instead.  
Any advice would be greatly appreciated! 😃

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 11, 2015, 8:15am UTC](https://discuss.elastic.co/t/failed-to-parse-timestamp/36920/2 "2015-12-11T08:15:55Z")

</div>

Why not just use the date filter to parse the date into ISO8601 format (including milliseconds) and use a mapping that supports ISO8601?

But if you insist on the current mapping, I suggest this to append .000 if there are no milliseconds present:

```auto
if [tslice] !~ /\.[0-9]+$/ {
  mutate {
    update => {
      "tslice" => "%{tslice}.000"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![sombilat](https://avatars.discourse-cdn.com/v4/letter/s/779978/32.png) [@sombilat](https://discuss.elastic.co/u/sombilat)\
**Post date:** [December 11, 2015, 2:56pm UTC](https://discuss.elastic.co/t/failed-to-parse-timestamp/36920/3 "2015-12-11T14:56:09Z")

</div>

Hello Magnus Baeck,

Thank you the solution worked perfectly. Correct me if I am wrong, the pattern of "/.[0-9]+$/" is a regular expression?

I see it has a pattern, if it sees a . a series of number mus follow. Is it correct?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 11, 2015, 3:17pm UTC](https://discuss.elastic.co/t/failed-to-parse-timestamp/36920/4 "2015-12-11T15:17:38Z")

</div>

> Thank you the solution worked perfectly. Correct me if I am wrong, the pattern of "/.[0-9]+$/" is a regular expression?

Yes.

> I see it has a pattern, if it sees a . a series of number mus follow. Is it correct?

Yes. The expression matches if the `tslice` fields ends with one or more digits, preceded by a period.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:18am UTC](https://discuss.elastic.co/t/failed-to-parse-timestamp/36920/5 "2017-07-06T05:18:51Z")

</div>


