# \[FATAL\] 2018-05-04 16:06:38.656 \[LogStash::Runner\] runner - The given configuration is invalid. Reason: Illegal pattern component: T when trying to parse date

**URL:** <https://discuss.elastic.co/t/fatal-2018-05-04-16-06-38-656-logstash-runner-runner-the-given-configuration-is-invalid-reason-illegal-pattern-component-t-when-trying-to-parse-date/130643>\
**Category:** Logstash\
**Created:** [May 4, 2018, 2:20pm UTC](https://discuss.elastic.co/t/fatal-2018-05-04-16-06-38-656-logstash-runner-runner-the-given-configuration-is-invalid-reason-illegal-pattern-component-t-when-trying-to-parse-date/130643 "2018-05-04T14:20:24Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dyl](https://avatars.discourse-cdn.com/v4/letter/d/5fc32e/32.png) [@dyl](https://discuss.elastic.co/u/dyl)\
**Post date:** [May 4, 2018, 2:20pm UTC](https://discuss.elastic.co/t/fatal-2018-05-04-16-06-38-656-logstash-runner-runner-the-given-configuration-is-invalid-reason-illegal-pattern-component-t-when-trying-to-parse-date/130643/1 "2018-05-04T14:20:24Z")

</div>

Hello everybody,

I've got a CSV document which is imported thanks to fileabeat to logstash input, then it is filtered and then goes to ES to be saw in Kabana.

I want to parse a date from this CSV file to use it for the @timestamp.

This date is : "`2018-02-28 23:00 GMT`" (incremented each day of the month..)

so my pipeline looks like this :

```
input
{
  beats
  {
    port => 5044
  }
}
filter
{
  csv
  {
    separator => ";"
    columns => ["jour","type","total"]
    convert =>
        {
            "total" => "float"
        }
  }
  if [message] =~ /^jour/
  {
   drop {}
  }
  date
  {
    match => ["jour", "yyyy-MM-dd HH:mm GMT"]
  }
}
output
{
  elasticsearch
  {
    hosts => "http://localhost:9200"
    index => "ironport"
  }
  stdout{}
}

```

But when I test my pipeline before to use it, i've got this error :

`[FATAL] 2018-05-04 16:06:38.656 [LogStash::Runner] runner - The given configuration is invalid. Reason: Illegal pattern component: T`

Is it the "GMT" which is problematic ? If yes, how can I do to deal with this date format ?

Can somebody help me ?

Thx for all for your help.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 4, 2018, 4:26pm UTC](https://discuss.elastic.co/t/fatal-2018-05-04-16-06-38-656-logstash-runner-runner-the-given-configuration-is-invalid-reason-illegal-pattern-component-t-when-trying-to-parse-date/130643/2 "2018-05-04T16:26:30Z")

</div>

```
date { match => ["message", "yyy-MM-dd HH:mm ZZZ"] }
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 4, 2018, 7:42pm UTC](https://discuss.elastic.co/t/fatal-2018-05-04-16-06-38-656-logstash-runner-runner-the-given-configuration-is-invalid-reason-illegal-pattern-component-t-when-trying-to-parse-date/130643/3 "2018-05-04T19:42:00Z")

</div>

If you want to match the literal string "GMT" you need to surround it in single quotes. If you want the date filter to parse the timezone name I don't think that'll work.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 4, 2018, 8:29pm UTC](https://discuss.elastic.co/t/fatal-2018-05-04-16-06-38-656-logstash-runner-runner-the-given-configuration-is-invalid-reason-illegal-pattern-component-t-when-trying-to-parse-date/130643/4 "2018-05-04T20:29:49Z")

</div>

> [@magnusbaeck](#):
>
> If you want the date filter to parse the timezone name I don't think that'll work.

In 6.2.3 it works. It is listed as an alias on the Joda page. EST is now on there too as a canonical id!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 1, 2018, 8:30pm UTC](https://discuss.elastic.co/t/fatal-2018-05-04-16-06-38-656-logstash-runner-runner-the-given-configuration-is-invalid-reason-illegal-pattern-component-t-when-trying-to-parse-date/130643/5 "2018-06-01T20:30:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
