# Grok and date filter

**URL:** <https://discuss.elastic.co/t/grok-and-date-filter/55376>\
**Category:** Logstash\
**Created:** [July 13, 2016, 6:32am UTC](https://discuss.elastic.co/t/grok-and-date-filter/55376 "2016-07-13T06:32:28Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chanawit\_Onchoo](https://avatars.discourse-cdn.com/v4/letter/c/d2c977/32.png) [@Chanawit\_Onchoo](https://discuss.elastic.co/u/Chanawit_Onchoo)\
**Post date:** [July 13, 2016, 6:32am UTC](https://discuss.elastic.co/t/grok-and-date-filter/55376/1 "2016-07-13T06:32:28Z")

</div>

Hello

I have some question to ask about date filter how can I try to change type that get from grok to date

(input) :  
notBefore=Nov 10 00:00:00 2015 GMT notAfter=Nov 28 23:59:59 2016 GMT issuer= /C=US/O=SSS/OU=STT/CN=Symantec Class 3 EV SSL CA - G3 subject= /1asdasdasdasdasdasd.Com

my logstash conf file is looked like this

> input {  
> file {  
> path =\> "/opt/log/\*.log"  
> start\_position =\> beginning  
> sincedb\_path =\> "/dev/null"  
> }  
> }  
> filter {  
> grok {  
> match =\> { "message" =\> "(?m)notBefore=%{DATA:Before} notAfter=%{DATA:After} issuer= /%{DATA:issuer}subject= /%{GREEDYDATA:subject}" }  
> }  
> date {  
> locale =\> en  
> match =\> ["Before", "MMM dd HH:mm:ss yyyy z"]  
> }  
> }  
> output {  
> elasticsearch { hosts =\> ["192.168.100.141:9200"]  
> }  
> stdout {}  
> }

But I cant see any data come to elasticsearch and when I try delete data filter it works fine

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 13, 2016, 6:42am UTC](https://discuss.elastic.co/t/grok-and-date-filter/55376/2 "2016-07-13T06:42:00Z")

</div>

Forget about Elasticsearch for now. Comment out your elasticsearch output and make this your only output: `stdout { codec => rubydebug }`. Try again. What do you get?

Do note that the date filter can't parse timezone _names_, i.e. it won't be able to parse "GMT".

---

<div class="post-metadata">

**Author:** ![Chanawit\_Onchoo](https://avatars.discourse-cdn.com/v4/letter/c/d2c977/32.png) [@Chanawit\_Onchoo](https://discuss.elastic.co/u/Chanawit_Onchoo)\
**Post date:** [July 13, 2016, 6:44am UTC](https://discuss.elastic.co/t/grok-and-date-filter/55376/3 "2016-07-13T06:44:31Z")

</div>

It's normal result

> "message" =\> "notBefore=Jun 18 00:00:00 2015 GMT notAfter=Sep 15 23:59:59 2016 GMT issuer= /C=US/O=Symantec Corporation/OU=Symantec Trust Network/CN=Symantec Class 3 EV SSL CA - G3 subject= /1.3.6.1.4.1.311.60.2.1.3=US/1.3.6.1.4.1.311.60.2.1.2=Delaware/businessCategory=Private Organization/serialNumber=2927442/C=US/postalCode=60603/ST=Illinois/L=Chicago/street=135 S La Salle St/O=Bank of America Corporation/OU=AIT 59915 - Network Infrastructure/CN=[bankofamerica.com](http://bankofamerica.com)",  
> "@version" =\> "1",  
> "@timestamp" =\> "2015-06-18T00:00:00.000Z",  
> "path" =\> "/opt/log/bankofamerica.com.log",  
> "host" =\> "logstash01",  
> "Before" =\> "Jun 18 00:00:00 2015 GMT",  
> "After" =\> "Sep 15 23:59:59 2016 GMT",  
> "issuer" =\> "C=US/O=Symantec Corporation/OU=Symantec Trust Network/CN=Symantec Class 3 EV SSL CA - G3 ",  
> "subject" =\> "1.3.6.1.4.1.311.60.2.1.3=US/1.3.6.1.4.1.311.60.2.1.2=Delaware/businessCategory=Private Organization/serialNumber=2927442/C=US/postalCode=60603/ST=Illinois/L=Chicago/street=135 S La Salle St/O=Bank of America Corporation/OU=AIT 59915 - Network Infrastructure/CN=[bankofamerica.com](http://bankofamerica.com)"

---

<div class="post-metadata">

**Author:** ![Chanawit\_Onchoo](https://avatars.discourse-cdn.com/v4/letter/c/d2c977/32.png) [@Chanawit\_Onchoo](https://discuss.elastic.co/u/Chanawit_Onchoo)\
**Post date:** [July 13, 2016, 6:50am UTC](https://discuss.elastic.co/t/grok-and-date-filter/55376/4 "2016-07-13T06:50:25Z")

</div>

I just notice that date filter is not working as I always think so I need to apply target in date filter  
now I try use new logstash conf

> input {  
> file {  
> path =\> "/opt/log/\*.log"  
> start\_position =\> beginning  
> sincedb\_path =\> "/dev/null"  
> }  
> }  
> filter {  
> grok {  
> match =\> { "message" =\> "(?m)notBefore=%{DATA:Before} GMT notAfter=%{DATA:After} GMT issuer= /%{DATA:issuer}subject= /%{GREEDYDATA:subject}" }  
> }  
> date {  
> locale =\> en  
> match =\> ["Before", "MMM dd HH:mm:ss yyyy"]  
> target =\> "Before"  
> }  
> }  
> output {  
> elasticsearch { hosts =\> ["192.168.100.141:9200"]  
> }  
> stdout { codec =\> rubydebug }  
> }

And it's work ! so I want to ask more about how can I apply to multiple target (like Before/After) and why when I go to kibana logstash field I still see Before as String not date

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 13, 2016, 7:15am UTC](https://discuss.elastic.co/t/grok-and-date-filter/55376/5 "2016-07-13T07:15:35Z")

</div>

> how can I apply to multiple target (like Before/After)

Use multiple date filters.

> and why when I go to kibana logstash field I still see Before as String not date

Probably because the field already had been mapped as a string. Mappings of fields can't be changed without reindexing.

---

<div class="post-metadata">

**Author:** ![Chanawit\_Onchoo](https://avatars.discourse-cdn.com/v4/letter/c/d2c977/32.png) [@Chanawit\_Onchoo](https://discuss.elastic.co/u/Chanawit_Onchoo)\
**Post date:** [July 13, 2016, 7:22am UTC](https://discuss.elastic.co/t/grok-and-date-filter/55376/6 "2016-07-13T07:22:20Z")

</div>

Thank you very much! I am very appreciated for your support!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:48am UTC](https://discuss.elastic.co/t/grok-and-date-filter/55376/7 "2017-07-06T04:48:18Z")

</div>


