# Get datetime from logs

**URL:** <https://discuss.elastic.co/t/get-datetime-from-logs/277175>\
**Category:** Logstash\
**Created:** [June 28, 2021, 6:51am UTC](https://discuss.elastic.co/t/get-datetime-from-logs/277175 "2021-06-28T06:51:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rashmika\_Gamage](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmika_gamage/32/88321_2.png) [@Rashmika\_Gamage](https://discuss.elastic.co/u/Rashmika_Gamage)\
**Post date:** [June 28, 2021, 6:51am UTC](https://discuss.elastic.co/t/get-datetime-from-logs/277175/1 "2021-06-28T06:51:49Z")

</div>

I am trying to get logs to Kibana using logstash and filebeats. However kibana doesn't take data and time (which in the logs) as datetime. Instead in takes as string and cannot change format as well .  
Appreciate your help  
Here are the configurations

logstash filter

> filter {  
> grok {  
> match =\> {  
> "message" =\> "(?application\_[^/]_)[^]_ [%{TIMESTAMP\_ISO8601:logTime}] %{LOGLEVEL:logLevel} %{GREEDYDATA:LogMessage}" }  
> }  
> }

sample logs

> /yarn/container-logs/application\_1621858977521\_0151/container\_1621858977521\_0151\_01\_000004 [2021-06-28 02:38:10,542] INFO Started daemon with process name: 7796@slave1 (org.apache.spark.executor.CoarseGrainedExecutorBackend)  
> /yarn/container-logs/application\_1621858977521\_0151/container\_1621858977521\_0151\_01\_000004 [2021-06-28 02:38:10,547] INFO Registered signal handler for TERM (org.apache.spark.util.SignalUtils)  
> /yarn/container-logs/application\_1621858977521\_0151/container\_1621858977521\_0151\_01\_000004 [2021-06-28 02:38:10,548] INFO Registered signal handler for HUP (org.apache.spark.util.SignalUtils)

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [June 28, 2021, 11:32am UTC](https://discuss.elastic.co/t/get-datetime-from-logs/277175/2 "2021-06-28T11:32:58Z")

</div>

Hi,

Your pattern does not follow the grok syntax.  
First, if you want to create a custom pattern, you have to write `(?<fiel>patternHere)` instead of `(?field_patterHere)`.  
Last, if you search `[` or `]`, you have to put backslash in front of it.

Pattern that match the syntax of your logs :

```auto
%{NOTSPACE:application} \[%{TIMESTAMP_ISO8601:logTime}\] %{LOGLEVEL:logLevel} %{GREEDYDATA:LogMessage}

```

For date conversion, look the date filter.  
Cad.

---

<div class="post-metadata">

**Author:** ![Rashmika\_Gamage](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmika_gamage/32/88321_2.png) [@Rashmika\_Gamage](https://discuss.elastic.co/u/Rashmika_Gamage)\
**Post date:** [June 29, 2021, 3:45am UTC](https://discuss.elastic.co/t/get-datetime-from-logs/277175/3 "2021-06-29T03:45:10Z")

</div>

Thank you Cad. Appreciate it

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 27, 2021, 3:45am UTC](https://discuss.elastic.co/t/get-datetime-from-logs/277175/4 "2021-07-27T03:45:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
