# Filebeat - Date processor - Log file content without date

**URL:** <https://discuss.elastic.co/t/filebeat-date-processor-log-file-content-without-date/229489>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 23, 2020, 2:28pm UTC](https://discuss.elastic.co/t/filebeat-date-processor-log-file-content-without-date/229489 "2020-04-23T14:28:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![pjo](https://avatars.discourse-cdn.com/v4/letter/p/d9b06d/32.png) [@pjo](https://discuss.elastic.co/u/pjo)\
**Post date:** [April 23, 2020, 2:28pm UTC](https://discuss.elastic.co/t/filebeat-date-processor-log-file-content-without-date/229489/1 "2020-04-23T14:28:56Z")

</div>

Hello there,

I'm new on this product.

here is my question

I use filebeat to crawl log file and send content to logstash frontend.

Usually my logs files contains on each row a full date format. File is able to read to store document with good timestamp info in ES.

But I have a log file that doesn't have full date in each row but only hours (date is in the log filename)

Each day a new log file is created and contains day related event.

Example :  
Log file name : mylogFile-20200423.log

Log file content at each row :  
`01:00:07.802 (18924:16416) U-PE: 20000013 MWIOff `

The regexp could be :  
`[Hours]:[Min]:[Sec].[msec] ([specific_ID]) [unparseable various datas]`

Online documentation said that i could use "Date processor"

[https://www.elastic.co/guide/en/elasticsearch/reference/7.6/date-processor.html](https://www.elastic.co/guide/en/elasticsearch/reference/7.6/date-processor.html)

Is it possible to append the current system date (years,month,day) in addition to the hours retrieved in log file ?

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 23, 2020, 2:47pm UTC](https://discuss.elastic.co/t/filebeat-date-processor-log-file-content-without-date/229489/2 "2020-04-23T14:47:05Z")

</div>

Whenever Filebeat ingests an entry from a log file, it will create a field in the resulting event called `log.file.path`. This field will contain the complete path to the log file from where the entry was ingested. So, in your case, this would have values like `/path/to/my/logs/mylogFile-20200423.log`.

In your Logstash pipeline, you can perhaps use something like a `grok` filter to extract the date part from this field. And similarly you could extract the time part from your log entry. Then combine the two and pass the combined value to the Logstash `date` filter to set the correct `@timestamp` field value for each of your log entries / events.

---

<div class="post-metadata">

**Author:** ![pjo](https://avatars.discourse-cdn.com/v4/letter/p/d9b06d/32.png) [@pjo](https://discuss.elastic.co/u/pjo)\
**Post date:** [April 24, 2020, 7:49am UTC](https://discuss.elastic.co/t/filebeat-date-processor-log-file-content-without-date/229489/3 "2020-04-24T07:49:32Z")

</div>

@shaunak thanks for this answer 🙂

Indeed i could rebuild a proper date based on 2 different string in logstash side.

I'll check this

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 22, 2020, 7:49am UTC](https://discuss.elastic.co/t/filebeat-date-processor-log-file-content-without-date/229489/4 "2020-05-22T07:49:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
