# Filter date doesn't work

**URL:** <https://discuss.elastic.co/t/filter-date-doesnt-work/184218>\
**Category:** Logstash\
**Created:** [June 4, 2019, 3:25pm UTC](https://discuss.elastic.co/t/filter-date-doesnt-work/184218 "2019-06-04T15:25:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![soufiane1](https://avatars.discourse-cdn.com/v4/letter/s/dfb087/32.png) [@soufiane1](https://discuss.elastic.co/u/soufiane1)\
**Post date:** [June 4, 2019, 3:25pm UTC](https://discuss.elastic.co/t/filter-date-doesnt-work/184218/1 "2019-06-04T15:25:02Z")

</div>

Hello everyone,

I have a column called "Date et heure" that is formatted as [dd/MM/YY HH:mm] (ie 04/12/2019 17:45),  
I am using a date filter in order to treat this as a date when passing to ElasticSearch but it doesn't work, for example for "04/12/2019 17:45" it only loads "4",

Here is my config:

#######################################################

filter  
{  
csv  
{  
separator =\> ","

```
	columns => ["Date et heure","Utilisateur","Code","Libelle evenement","Code retour","Application","Code site","Objet Start","Usage cache","Valeur avant modif","Valeur apres modif"]
}

	
mutate{

	convert => { 
		
		"Date et heure" => "string"
		"Utilisateur" => "string" 
		"Code" => "integer" 
		"Libellé évènement" => "string" 
		"Code retour" => "integer" 
		"Application" => "string" 
		"Code site" => "integer" 
		"Objet Start" => "string" 
		"Usage cache" => "string" 						
		"Valeur avant modif" => "string" 
		"Valeur après modif" => "string"	
	
	}
	
	#Gestion des accents
	rename => { "Libelle evenement" => "Libellé évènement"  
				"Valeur apres modif" => "Valeur après modif" }
					

}

date {	
	
	match => ["Date et heure", "dd/MM/YY HH:mm"] 
	
}

```

}

############################################################

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 4, 2019, 3:32pm UTC](https://discuss.elastic.co/t/filter-date-doesnt-work/184218/2 "2019-06-04T15:32:38Z")

</div>

The example you showed has a 4-digit year while you specified a 2-digit year in your pattern. Does it make a difference if you correct this? Does the date filter the populate the @timestamp field correctly?

---

<div class="post-metadata">

**Author:** ![soufiane1](https://avatars.discourse-cdn.com/v4/letter/s/dfb087/32.png) [@soufiane1](https://discuss.elastic.co/u/soufiane1)\
**Post date:** [June 4, 2019, 3:44pm UTC](https://discuss.elastic.co/t/filter-date-doesnt-work/184218/3 "2019-06-04T15:44:13Z")

</div>

thank you for your reply i have corrected the year number of digits but still the same,  
I didn't understood your second question, can you be more clear pls ?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 4, 2019, 3:48pm UTC](https://discuss.elastic.co/t/filter-date-doesnt-work/184218/4 "2019-06-04T15:48:58Z")

</div>

The date filter by default populates the `@timestamp` field (in UTC timezone)) and does not modify the source field. Does it get populated correctly?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 4, 2019, 5:19pm UTC](https://discuss.elastic.co/t/filter-date-doesnt-work/184218/5 "2019-06-04T17:19:59Z")

</div>

I was surprised to find that YY will match a 4-digit year!

```
input { generator { count => 1 lines => [''] } }
filter {
    mutate { add_field => { "Date et heure" => "04/12/2019 17:45" } }
    date { match => ["Date et heure", "dd/MM/YY HH:mm"] }
}
output { stdout { codec => rubydebug { metadata => false } } }

```

gets me

```
"Date et heure" => "04/12/2019 17:45",
   "@timestamp" => 2019-12-04T17:45:00.000Z,
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 2, 2019, 5:25pm UTC](https://discuss.elastic.co/t/filter-date-doesnt-work/184218/6 "2019-07-02T17:25:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
