# Grok pattern for date

**URL:** https://discuss.elastic.co/t/grok-pattern-for-date/181322
**Category:** Logstash
**Created:** [May 16, 2019, 7:15am UTC](https://discuss.elastic.co/t/grok-pattern-for-date/181322 "2019-05-16T07:15:32Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![talial](https://avatars.discourse-cdn.com/v4/letter/t/3be4f8/32.png) [@talial](https://discuss.elastic.co/u/talial)
#### Post date: [May 16, 2019, 7:15am UTC](https://discuss.elastic.co/t/grok-pattern-for-date/181322/1 "2019-05-16T07:15:32Z")

</div>

Hi  
I have a log file that I want to parse to elasticsearch using logstash.  
In the log I have a date like that:  
`2019-04-18+05:48:54.470`  
I trying to find how to grok this timestamp with kibana Grok Debugger  
Trying the following pattern but with no success:  
%{HTTPDATE:timestamp}  
%{DATESTAMP:timestamp}  
%{TIMESTAMP\_ISO8601:timestamp}  
Any suggestion?

Thanks  
Talia

---

<div class="post-metadata">

### Author: ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)
#### Post date: [May 16, 2019, 8:20am UTC](https://discuss.elastic.co/t/grok-pattern-for-date/181322/2 "2019-05-16T08:20:38Z")

</div>

> [@talial](#):
>
> 2019-04-18+05:48:54.470

The closest pattern I could find that is known by Logstash is this

> TOMCAT\_DATESTAMP 20%{YEAR}-%{MONTHNUM}-%{MONTHDAY} %{HOUR}:?%{MINUTE}(?::?%{SECOND}) %{ISO8601\_TIMEZONE}

The `+` between the date and time doesn't seem to be in any so you will have to make your own.

This pattern should work

```
%{YEAR}-%{MONTHNUM}-%{MONTHDAY}\+%{TIME}

```

---

<div class="post-metadata">

### Author: ![talial](https://avatars.discourse-cdn.com/v4/letter/t/3be4f8/32.png) [@talial](https://discuss.elastic.co/u/talial)
#### Post date: [May 16, 2019, 8:50am UTC](https://discuss.elastic.co/t/grok-pattern-for-date/181322/3 "2019-05-16T08:50:30Z")

</div>

Thanks  
Just to be sure, for combinning all the feilds that I get from this pattern I have to use the mutate in the logstash file?  
like this:

> mutate {  
> add\_field =\> {  
> "timestamps" =\> "%{YEAR}-%{MONTHNUM}-%{MONTHDAY} %{HOUR}:?%{MINUTE}(?::?%{SECOND}) %{ISO8601\_TIMEZONE}"  
> }  
> remove\_field =\> ["YEAR", "MONTHNUM","MONTHDAY","HOUR","MINUTE","SECOND","ISO8601\_TIMEZONE"]  
> }

---

<div class="post-metadata">

### Author: ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)
#### Post date: [May 16, 2019, 12:56pm UTC](https://discuss.elastic.co/t/grok-pattern-for-date/181322/4 "2019-05-16T12:56:26Z")

</div>

That was a `grok` pattern. You can put it in a [pattern file](https://www.elastic.co/guide/en/logstash/7.0/plugins-filters-grok.html#plugins-filters-grok-patterns_dir) or specify it inside the grok filter like

```
grok {
  match => { "filed_name" => "YOUR FULL LINE GROK PATTERN GOES HERE. YOU CAN USE %{MY_TIME:timestamp} FOR THE DATE PART"
  pattern_definitions => {
    "MY_TIME" => "%{YEAR}-%{MONTHNUM}-%{MONTHDAY}\+%{TIME}"
  }
}

```

Not entirely sure what the best way to turn the time into @timestamp would be...

---

<div class="post-metadata">

### Author: ![talial](https://avatars.discourse-cdn.com/v4/letter/t/3be4f8/32.png) [@talial](https://discuss.elastic.co/u/talial)
#### Post date: [May 16, 2019, 1:10pm UTC](https://discuss.elastic.co/t/grok-pattern-for-date/181322/5 "2019-05-16T13:10:20Z")

</div>

OK  
Thanks a lot

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [May 16, 2019, 1:19pm UTC](https://discuss.elastic.co/t/grok-pattern-for-date/181322/6 "2019-05-16T13:19:16Z")

</div>

[This](https://discuss.elastic.co/t/convert-date-to-string-string/181128/3) shows the pattern you need to parse it.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 13, 2019, 1:19pm UTC](https://discuss.elastic.co/t/grok-pattern-for-date/181322/7 "2019-06-13T13:19:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
