# Getting \_dateparsefailure on date filter

**URL:** <https://discuss.elastic.co/t/getting-dateparsefailure-on-date-filter/169575>\
**Category:** Logstash\
**Created:** [February 22, 2019, 12:06pm UTC](https://discuss.elastic.co/t/getting-dateparsefailure-on-date-filter/169575 "2019-02-22T12:06:15Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![bigster](https://avatars.discourse-cdn.com/v4/letter/b/8e7dd6/32.png) [@bigster](https://discuss.elastic.co/u/bigster)\
**Post date:** [February 22, 2019, 12:06pm UTC](https://discuss.elastic.co/t/getting-dateparsefailure-on-date-filter/169575/1 "2019-02-22T12:06:16Z")

</div>

Hi,

I'm trying to do this stuff:

date {  
match =\> ["date\_created", "ISO8601"]  
target =\> "@timestamp"  
}  
and  
date {  
match =\> ["date\_created", "yyyy-MM-dd HH:mm:ss,SSS"]  
target =\> "@timestamp"  
}

But everything fails.

The date\_created in Elastic has this pattern:  
"date\_created": "2019-02-22T11:19:59.802Z"

Anyone knows what is the problem?

Cheers

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 22, 2019, 1:42pm UTC](https://discuss.elastic.co/t/getting-dateparsefailure-on-date-filter/169575/2 "2019-02-22T13:42:08Z")

</div>

The second one does not match, but the first one (ISO8601) should set @timestamp correctly. What exactly do you mean by "everything fails"?

---

<div class="post-metadata">

**Author:** ![bigster](https://avatars.discourse-cdn.com/v4/letter/b/8e7dd6/32.png) [@bigster](https://discuss.elastic.co/u/bigster)\
**Post date:** [February 22, 2019, 1:55pm UTC](https://discuss.elastic.co/t/getting-dateparsefailure-on-date-filter/169575/3 "2019-02-22T13:55:45Z")

</div>

Hi,

Like i said.  
I put the ISO8601 pattern and i also get the error \_dateparsefailure.

Cheers

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 22, 2019, 2:35pm UTC](https://discuss.elastic.co/t/getting-dateparsefailure-on-date-filter/169575/4 "2019-02-22T14:35:15Z")

</div>

It works for me.

```
input { generator { count => 1 message => '' } }
filter {
    mutate { add_field => { "date_created" => "2019-02-22T11:19:59.802Z" } }
    date { match => ["date_created", "ISO8601"] }
}
output { stdout { codec => rubydebug { metadata => false } } }

```

gets me

```
  "@timestamp" => 2019-02-22T11:19:59.802Z,
"date_created" => "2019-02-22T11:19:59.802Z",
```

---

<div class="post-metadata">

**Author:** ![bigster](https://avatars.discourse-cdn.com/v4/letter/b/8e7dd6/32.png) [@bigster](https://discuss.elastic.co/u/bigster)\
**Post date:** [February 22, 2019, 2:55pm UTC](https://discuss.elastic.co/t/getting-dateparsefailure-on-date-filter/169575/5 "2019-02-22T14:55:22Z")

</div>

This is very strange, i redirect the ouput to a file and the date\_created has the same pattern as you:

{  
"system\_timestamp" =\> 2019-02-22T14:41:30.294Z,  
"operation\_id" =\> "f10c4906-36af-11e9-ba43-0a030bd70000",  
"lang\_code" =\> "",  
"application\_id" =\> 195,  
"ext\_origin" =\> "",  
"message\_type" =\> "Req",  
"status\_code" =\> "X0",  
"api\_organization\_id" =\> "",  
"client\_id" =\> 1,  
"@timestamp" =\> 2019-02-22T14:46:01.918Z,  
"channel" =\> "",  
"@version" =\> "1",  
"approach" =\> "C",  
"num\_retries" =\> "",  
"status\_msg" =\> "",  
"transaction\_id" =\> "f108a7c4-36af-11e9-ba43-0a030bd70000",  
"ext\_host" =\> "",  
"ext\_session\_id" =\> "",  
"api\_client\_id" =\> "",  
"ext\_transaction\_id" =\> "",  
"application" =\> "",  
"tags" =\> [  
**[0] "\_dateparsefailure",**  
[1] "taskStarted"  
],  
**"date\_created" =\> 2019-02-22T14:41:30.280Z,**  
"api\_transaction\_id" =\> "",  
"operation\_version" =\> "1.0",  
"communication\_id" =\> 51453625  
}

The difference from your example is that your date is presented like a string "" and mine no "date\_created" =\> 2019-02-22T14:41:30.280Z.

This makes any sense? Can be that this difference is the cause of this behavior?

Cheers.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 22, 2019, 3:06pm UTC](https://discuss.elastic.co/t/getting-dateparsefailure-on-date-filter/169575/6 "2019-02-22T15:06:45Z")

</div>

> [@bigster](#):
>
> The difference from your example is that your date is presented like a string "" and mine no "date\_created" =\> 2019-02-22T14:41:30.280Z.

Yes, that's critical. In logstash your date\_created field is already a LogStash::timestamp. A date filter [cannot parse that](https://github.com/logstash-plugins/logstash-filter-date/issues/95).

The traditional workaround is

```
mutate { convert { "date_created" => "string" } }

```

---

<div class="post-metadata">

**Author:** ![bigster](https://avatars.discourse-cdn.com/v4/letter/b/8e7dd6/32.png) [@bigster](https://discuss.elastic.co/u/bigster)\
**Post date:** [February 22, 2019, 4:38pm UTC](https://discuss.elastic.co/t/getting-dateparsefailure-on-date-filter/169575/7 "2019-02-22T16:38:34Z")

</div>

That's it.  
You solve it.

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2019, 4:38pm UTC](https://discuss.elastic.co/t/getting-dateparsefailure-on-date-filter/169575/8 "2019-03-22T16:38:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
