# Grok parsing timestamp with 2 fields

**URL:** <https://discuss.elastic.co/t/grok-parsing-timestamp-with-2-fields/286312>\
**Category:** Logstash\
**Created:** [October 10, 2021, 3:58pm UTC](https://discuss.elastic.co/t/grok-parsing-timestamp-with-2-fields/286312 "2021-10-10T15:58:25Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![alon\_carmelly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alon_carmelly/32/118670_2.png) [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Post date:** [October 10, 2021, 3:58pm UTC](https://discuss.elastic.co/t/grok-parsing-timestamp-with-2-fields/286312/1 "2021-10-10T15:58:25Z")

</div>

Hi,  
I got this log which has 2 fields of time stamp. How would I go about parsing it, couldn't find any examples online !

`{"type": "GreatLog", **"date": "10/3/2021", "time": "6:21:35 AM"** , "message": "Take a Measurement ", "data": "<94;1;0;0;97;168;19;136;0;52;(0)><134217728>", "clientntId": "959", "ddid": "D9-9999-004F"}`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 10, 2021, 5:08pm UTC](https://discuss.elastic.co/t/grok-parsing-timestamp-with-2-fields/286312/2 "2021-10-10T17:08:52Z")

</div>

I would suggest a json filter to parse the JSON, then mutate+add\_field to combine the date and time fields using sprintf references, then a date filter. There are many, many examples of each of those in this forum.

---

<div class="post-metadata">

**Author:** ![alon\_carmelly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alon_carmelly/32/118670_2.png) [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Post date:** [October 11, 2021, 5:55am UTC](https://discuss.elastic.co/t/grok-parsing-timestamp-with-2-fields/286312/3 "2021-10-11T05:55:20Z")

</div>

@Badger Many thanks to you, I wasn't searching in the right place.  
I didn't know parsing was a first step, I thought it was done automatically.  
I did try this example but wasn't sure about the syntex

```auto
if "GW" in [path] {

    mutate { add_field => { "[@metadata][ts]" => "%{date} %{time}" } }

    date { match => ["[@metadata][ts]", "%{DATE_US:date} hh:mm:ss a" ] }

  }

```

How does the [ts] relate to the @metadata?

Cheers

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 11, 2021, 4:15pm UTC](https://discuss.elastic.co/t/grok-parsing-timestamp-with-2-fields/286312/4 "2021-10-11T16:15:05Z")

</div>

The [@metadata] field contains fields that are visible in the pipeline, but are ignored by the outputs, so it is useful to store interim results whilst processing events.

---

<div class="post-metadata">

**Author:** ![alon\_carmelly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alon_carmelly/32/118670_2.png) [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Post date:** [October 17, 2021, 8:01am UTC](https://discuss.elastic.co/t/grok-parsing-timestamp-with-2-fields/286312/5 "2021-10-17T08:01:01Z")

</div>

Can you show me how it would be done so I can revers-engineer it in order to understand?  
{"type": "GreatLog", **"date": "10/3/2021", "time": "6:21:35 AM"** , "message": "Take a Measurement ", "data": "\<94;1;0;0;97;168;19;136;0;52;(0)\>\<134217728\>", "clientntId": "959", "ddid": "D9-9999-004F"}

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 17, 2021, 2:38pm UTC](https://discuss.elastic.co/t/grok-parsing-timestamp-with-2-fields/286312/6 "2021-10-17T14:38:45Z")

</div>

Try this config:

```auto
filter {
    json {
        source => "message"
    }
    mutate {
        add_field => { "[@metadata][ts]" => "%{date} %{time}" }
    }
    date {
        match => ["[@metadata][ts]", "M/d/yyyy h:mm:ss a"]
    }
}

```

It will give an output like this:

```auto
{
      "@version" => "1",
          "host" => "logstash-host-name",
          "date" => "10/3/2021",
          "ddid" => "D9-9999-004F",
    "clientntId" => "959",
    "@timestamp" => 2021-10-03T06:21:35.000Z,
          "time" => "6:21:35 AM",
       "message" => "Take a Measurement ",
          "type" => "GreatLog",
          "data" => "<94;1;0;0;97;168;19;136;0;52;(0)><134217728>"
}

```

Also, the `@timestamp` field will always be in UTC, if your original date is not in UTC you will need to use the option `timezone` in the `date` filter to tell logstash the timezone of your date.

---

<div class="post-metadata">

**Author:** ![alon\_carmelly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alon_carmelly/32/118670_2.png) [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Post date:** [October 19, 2021, 6:28am UTC](https://discuss.elastic.co/t/grok-parsing-timestamp-with-2-fields/286312/7 "2021-10-19T06:28:41Z")

</div>

Thank you very much !!! I am still not sure how the syntax works.  
does [@metadata][ts] means concatenation?  
is [ts] just a short name for timestamp ?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 19, 2021, 12:20pm UTC](https://discuss.elastic.co/t/grok-parsing-timestamp-with-2-fields/286312/8 "2021-10-19T12:20:23Z")

</div>

> [@alon\_carmelly](#):
>
> does [@metadata][ts] means concatenation?  
> is [ts] just a short name for timestamp ?

It is just a random field name, `@metadata` is a json object and `ts` is a field inside this json object, you can use anything.

For example:

```auto
{ 
   "@metadata": {
        "ts": "your-value",
        "anything": "another-value"
    }
}

```

This means that you have two fields, `@metadata.ts` and `@metadata.anything`, when using those fields in logstash filter will need to use the square brackets to access them, like `[@metadata][ts]` and `[@metadata][anything]`.

---

<div class="post-metadata">

**Author:** ![alon\_carmelly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alon_carmelly/32/118670_2.png) [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Post date:** [October 20, 2021, 8:36am UTC](https://discuss.elastic.co/t/grok-parsing-timestamp-with-2-fields/286312/9 "2021-10-20T08:36:11Z")

</div>

@leandrojmp  
Thank you so much for taking the time and clearing it out for me !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 17, 2021, 8:36am UTC](https://discuss.elastic.co/t/grok-parsing-timestamp-with-2-fields/286312/10 "2021-11-17T08:36:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
