# Grok filter TIMESTAMP\_ISO8601 Logstash not working

**URL:** https://discuss.elastic.co/t/grok-filter-timestamp-iso8601-logstash-not-working/175812
**Category:** Logstash
**Created:** [April 8, 2019, 10:08am UTC](https://discuss.elastic.co/t/grok-filter-timestamp-iso8601-logstash-not-working/175812 "2019-04-08T10:08:51Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![hatienkma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hatienkma/32/11066_2.png) [@hatienkma](https://discuss.elastic.co/u/hatienkma)
#### Post date: [April 8, 2019, 10:08am UTC](https://discuss.elastic.co/t/grok-filter-timestamp-iso8601-logstash-not-working/175812/1 "2019-04-08T10:08:51Z")

</div>

Hello,

I have problem and need help.

This is my logfile type:

`2019-01-28 07:37:25 52.62.158.16 - HTTP 192.168.25.80 443 GET /cpadmin/jquery-ui.min.js - 304 573 197 0 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+coc_coc_browser/77.0.126+Chrome/71.0.3578.126+Safari/537.36 JSESSIONID=0001EDFQ51w4GbNyiY8zUAlBhee:-1986MV https://google.com/search?q=demo`

This is logstash config:

```
input {
  beats {
	port => 5044
  }
}
filter {
	
	grok {
	  match => { "message" => "%{TIMESTAMP_ISO8601:timestampx} %{IPV4:c_ip} %{NOTSPACE:cs_username} %{NOTSPACE:s_sitename} %{IPV4:s_ip} %{NUMBER:s_port} %{WORD:method} %{URIPATH:uri_path} %{NOTSPACE:custom_string_01} %{NUMBER:status} %{NUMBER:bytessent} %{NUMBER:bytesrecvd} %{NUMBER:timetaken} %{NOTSPACE:version} %{NOTSPACE:user_agent} %{NOTSPACE:custom_string_02} %{NOTSPACE:referer}"}
	}
	date {
	  match => ["timestampx", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
	}
	geoip {
	  source => "c_ip"
	}
}

output {
  elasticsearch { 
	hosts => ["localhost:9200"]
	index => "logweb-%{+YYYY.MM.dd}"
  }
  stdout { codec => rubydebug }
}

```

Output timestampx is string: 2019-01-28 07:37:25 not date type.  
I want to replace timestamp by timestampx (timestampx convert from logfile, not use time system - same timestamp).

Thanks for your help.

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [April 8, 2019, 10:49am UTC](https://discuss.elastic.co/t/grok-filter-timestamp-iso8601-logstash-not-working/175812/2 "2019-04-08T10:49:53Z")

</div>

Your date filter format is incorrect. Try

```
 match => ["timestampx", "YYYY-MM-dd HH:mm:ss"]

```

That will set @timestamp

```
 "@timestamp" => 2019-01-28T12:37:25.000Z,

```

If you want timestampx to be a date instead of a string then set the target option on the date filter.

---

<div class="post-metadata">

### Author: ![hatienkma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hatienkma/32/11066_2.png) [@hatienkma](https://discuss.elastic.co/u/hatienkma)
#### Post date: [April 10, 2019, 7:12am UTC](https://discuss.elastic.co/t/grok-filter-timestamp-iso8601-logstash-not-working/175812/3 "2019-04-10T07:12:39Z")

</div>

Thanks @Badger. Its working.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 8, 2019, 7:12am UTC](https://discuss.elastic.co/t/grok-filter-timestamp-iso8601-logstash-not-working/175812/4 "2019-05-08T07:12:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
