# Grok date filter problem with french timestamp

**URL:** <https://discuss.elastic.co/t/grok-date-filter-problem-with-french-timestamp/314151>\
**Category:** Logstash\
**Created:** [September 11, 2022, 8:19pm UTC](https://discuss.elastic.co/t/grok-date-filter-problem-with-french-timestamp/314151 "2022-09-11T20:19:35Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![marwen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marwen/32/105159_2.png) [@marwen](https://discuss.elastic.co/u/marwen)\
**Post date:** [September 11, 2022, 8:19pm UTC](https://discuss.elastic.co/t/grok-date-filter-problem-with-french-timestamp/314151/1 "2022-09-11T20:19:35Z")

</div>

good day everyone, using elastic stack 17.7.5 I'm parsing log events to logstash  
the problem is date filter not working with my logs (catalina) here is example:

```auto
avr. 23, 2022 1:46:19 PM org.apache.coyote.AbstractProtocol init
sept. 02, 2019 2:46:50 PM org.apache.coyote.AbstractProtocol init
déc. 05, 2019 12:08:58 PM org.apache.coyote.AbstractProtocol init

```

you can see month name is in french abbreviation and timestamp ends with AM/PM  
here is date filter I used

```auto
date {
    match => ["logdate", "MMM. dd, YYYY H:mm:ss a"]
    timezone => "Europe/Paris"
    locale => "fr"
}

```

> when I change locale to "en" and edit month name to English in log to debug, it works  
> but not with french month name, even if I used locale and timezone options.  
> any solution ? without asking client to change their logs output, and thanks ❤

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 11, 2022, 11:15pm UTC](https://discuss.elastic.co/t/grok-date-filter-problem-with-french-timestamp/314151/2 "2022-09-11T23:15:55Z")

</div>

> [@marwen](#):
>
> `match => ["logdate", "MMM. dd, YYYY H:mm:ss a"]`

In the fr locale MMM consumes the `.`, so use `MMM dd, YYYY H:mm:ss a` without the period. In fact `dec.` _must_ have the trailing `.`. If it is missing you will get a \_dateparsefailure.

Note that Elastic have no say in this. Java defines which locales require a trailing . on abbreviated month names.

---

<div class="post-metadata">

**Author:** ![marwen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marwen/32/105159_2.png) [@marwen](https://discuss.elastic.co/u/marwen)\
**Post date:** [September 11, 2022, 11:41pm UTC](https://discuss.elastic.co/t/grok-date-filter-problem-with-french-timestamp/314151/3 "2022-09-11T23:41:46Z")

</div>

OMG thank you alot that is the problem, I was stuck there for days, you awesome ❤

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 12, 2022, 12:01am UTC](https://discuss.elastic.co/t/grok-date-filter-problem-with-french-timestamp/314151/4 "2022-09-12T00:01:59Z")

</div>

@Badger Strikes again!  
THX Today I learned!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 12, 2022, 12:13am UTC](https://discuss.elastic.co/t/grok-date-filter-problem-with-french-timestamp/314151/5 "2022-09-12T00:13:15Z")

</div>

That's it, just repicated here for French and also tested for Portuguese, which also has `.` in the abbreviated month names and it works.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 10, 2022, 12:13am UTC](https://discuss.elastic.co/t/grok-date-filter-problem-with-french-timestamp/314151/6 "2022-10-10T00:13:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
