# Getting \_dateparsefailure for a log file having two timestamps

**URL:** <https://discuss.elastic.co/t/getting-dateparsefailure-for-a-log-file-having-two-timestamps/289643>\
**Category:** Logstash\
**Created:** [November 18, 2021, 9:14pm UTC](https://discuss.elastic.co/t/getting-dateparsefailure-for-a-log-file-having-two-timestamps/289643 "2021-11-18T21:14:29Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Patr123](https://avatars.discourse-cdn.com/v4/letter/p/ac91a4/32.png) [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Post date:** [November 18, 2021, 9:14pm UTC](https://discuss.elastic.co/t/getting-dateparsefailure-for-a-log-file-having-two-timestamps/289643/1 "2021-11-18T21:14:29Z")

</div>

Hello My log file looks like:

```auto
[
  {
    "textPayload": "{'testkey': 'testvalue'}",
    "insertId": "12345-12345",
    "resource": {
      "type": "cloud_function",
      "labels": {
        "project_id": "project-p123",
        "region": "us-east4",
        "function_name": "testfunction"
      }
    },
    "timestamp": "2021-11-16T16:07:56.647Z",
    "severity": "INFO",
    "labels": {
      "execution_id": "uji09345"
    },
    "logName": "projects/project-p123/logs/cloudfunctions",
    "trace": "projects/project-p123/traces/uhne1234",
    "receiveTimestamp": "2021-11-16T16:08:06.721583231Z"
  }
]

```

And my filter looks like:

```auto
filter {
            date { 
                match => ["timestamp", "ISO8601"]
                target => ["@timestamp"]
                remove_field => ["timestamp"] 
            }
            date { 
                match => ["receiveTimestamp", "ISO8601"]
                target => ["receiveTimestamp"]
                #remove_field => ["receiveTimestamp"] 
            }
        }

```

All the other fields are coming in perfectly fine except the timestamps.  
Please help in fixing this issue.  
Thank you.

---

<div class="post-metadata">

**Author:** ![AquaX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aquax/32/92006_2.png) [@AquaX](https://discuss.elastic.co/u/AquaX)\
**Post date:** [November 18, 2021, 9:37pm UTC](https://discuss.elastic.co/t/getting-dateparsefailure-for-a-log-file-having-two-timestamps/289643/2 "2021-11-18T21:37:18Z")

</div>

Can you post an example of what it is coming in as?

---

<div class="post-metadata">

**Author:** ![Patr123](https://avatars.discourse-cdn.com/v4/letter/p/ac91a4/32.png) [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Post date:** [November 18, 2021, 9:52pm UTC](https://discuss.elastic.co/t/getting-dateparsefailure-for-a-log-file-having-two-timestamps/289643/3 "2021-11-18T21:52:03Z")

</div>

This is what I get:

 ![Screen Shot 2021-11-18 at 4.46.34 PM](https://us1.discourse-cdn.com/elastic/original/3X/c/5/c550804281692256b7634d51af3f6aa5df6c5e25.png)

---

<div class="post-metadata">

**Author:** ![AquaX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aquax/32/92006_2.png) [@AquaX](https://discuss.elastic.co/u/AquaX)\
**Post date:** [December 7, 2021, 4:10pm UTC](https://discuss.elastic.co/t/getting-dateparsefailure-for-a-log-file-having-two-timestamps/289643/4 "2021-12-07T16:10:44Z")

</div>

It's in the tags! You have a \_dateparsefailure. Also that screenshot is not the same as your example.  
🙂

This is probably because your `receiveTimestamp` may be too precise for the date filter.  
Anything beyond milliseconds is not parsed iirc.  
It don't see any problems with your `timestamp`

Have you tried not using the date filter and letting Elasticsearch recognize the timestamp on its own?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 4, 2022, 4:11pm UTC](https://discuss.elastic.co/t/getting-dateparsefailure-for-a-log-file-having-two-timestamps/289643/5 "2022-01-04T16:11:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
