# Having troubles parsing dates

**URL:** <https://discuss.elastic.co/t/having-troubles-parsing-dates/14573>\
**Category:** Elasticsearch\
**Created:** [November 25, 2013, 10:36am UTC](https://discuss.elastic.co/t/having-troubles-parsing-dates/14573 "2013-11-25T10:36:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ben\_Morrice](https://avatars.discourse-cdn.com/v4/letter/b/a8b319/32.png) [@Ben\_Morrice](https://discuss.elastic.co/u/Ben_Morrice)\
**Post date:** [November 25, 2013, 10:36am UTC](https://discuss.elastic.co/t/having-troubles-parsing-dates/14573/1 "2013-11-25T10:36:41Z")

</div>

Hello,

I have a basic logstash -\> elasticsearch instance running to parse apache  
logs; or at least I did. I don't know what has changed but elasticsearch is  
now bailing on my timestamp field and is not able to correctly parse it.

I'm using logstash standard grok patterns (COMBINEDAPACHELOG in this case)

Is anyone able to assist me? I'm sure this is a simple fix?!

Please see below an example from my elasticsearch log

[2013-11-25 09:49:47,585][DEBUG][action.bulk] [Slade,  
Hamilton] [logstash-2013.11.25][3] failed to execute bulk item (index)  
index {[logstash-2013.11.25][logs][CxGMkA9nSjej7jHdNfXh4g],  
source[{"message":"10.80.5.30 - - [25/Nov/2013:09:49:45 +0100] "GET  
/examplerequest HTTP/1.1" 200 11415 "-" "Jakarta  
Commons-HttpClient/3.1"","@timestamp":"2013-11-25T08:49:47.548Z","@version":"1","type":"webfrontend","file":"/var/loghttpdssl\_access\_log","host":"[example.com](http://example.com)","offset":"629386952","clientip":"10.80.5.30","ident":"-","auth":"-","timestamp":"25/Nov/2013:09:49:45  
+0100","verb":"GET","request":"/examplerequest","httpversion":"1.1","response":"200","bytes":"11415","referrer":""-"","agent":""Jakarta  
Commons-HttpClient/3.1"","tags":["apache"]}]}  
org.elasticsearch.index.mapper.MapperParsingException: failed to parse  
[timestamp]  
at  
org.elasticsearch.index.mapper.core.AbstractFieldMapper.parse(AbstractFieldMapper.java:398)  
at  
org.elasticsearch.index.mapper.object.ObjectMapper.serializeValue(ObjectMapper.java:618)  
at  
org.elasticsearch.index.mapper.object.ObjectMapper.parse(ObjectMapper.java:471)  
at  
org.elasticsearch.index.mapper.DocumentMapper.parse(DocumentMapper.java:513)  
at  
org.elasticsearch.index.mapper.DocumentMapper.parse(DocumentMapper.java:457)  
at  
org.elasticsearch.index.shard.service.InternalIndexShard.prepareCreate(InternalIndexShard.java:342)  
at  
org.elasticsearch.action.bulk.TransportShardBulkAction.shardIndexOperation(TransportShardBulkAction.java:401)  
at  
org.elasticsearch.action.bulk.TransportShardBulkAction.shardOperationOnPrimary(TransportShardBulkAction.java:155)  
at  
org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction.performOnPrimary(TransportShardReplicationOperationAction.java:556)  
at  
org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction$1.run(TransportShardReplicationOperationAction.java:426)  
at  
java.util.concurrent.ThreadPoolExecutor$Worker.runTask(ThreadPoolExecutor.java:895)  
at  
java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:918)  
at java.lang.Thread.run(Thread.java:662)  
Caused by: org.elasticsearch.index.mapper.MapperParsingException: failed to  
parse date field [25/Nov/2013:09:49:45 +0100], tried both date format  
[dateOptionalTime], and timestamp number with locale []  
at  
org.elasticsearch.index.mapper.core.DateFieldMapper.parseStringValue(DateFieldMapper.java:486)  
at  
org.elasticsearch.index.mapper.core.DateFieldMapper.innerParseCreateField(DateFieldMapper.java:424)  
at  
org.elasticsearch.index.mapper.core.NumberFieldMapper.parseCreateField(NumberFieldMapper.java:188)  
at  
org.elasticsearch.index.mapper.core.AbstractFieldMapper.parse(AbstractFieldMapper.java:387)  
... 12 more  
Caused by: java.lang.IllegalArgumentException: Invalid format:  
"25/Nov/2013:09:49:45 +0100" is malformed at "/Nov/2013:09:49:45 +0100"  
at  
org.elasticsearch.common.joda.time.format.DateTimeFormatter.parseMillis(DateTimeFormatter.java:754)  
at  
org.elasticsearch.index.mapper.core.DateFieldMapper.parseStringValue(DateFieldMapper.java:480)  
... 15 more

Thanks in advance!

Cheers,

Ben

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Phil\_Dougherty](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/phil_dougherty/32/1923_2.png) [@Phil\_Dougherty](https://discuss.elastic.co/u/Phil_Dougherty)\
**Post date:** [December 11, 2013, 8:26pm UTC](https://discuss.elastic.co/t/having-troubles-parsing-dates/14573/2 "2013-12-11T20:26:41Z")

</div>

I'm having the same exact issue. Running on a 4 node cluster and using ES  
0.90.3. Strangely this issue will randomly bite me, and it seems like it  
happens when the index is living on a certain server. Were you able to  
resolve this issue or could you provide some more information that may help  
me resolve this?

On Monday, November 25, 2013 5:36:41 AM UTC-5, Ben Morrice wrote:

> Hello,
> 
> I have a basic logstash -\> elasticsearch instance running to parse apache  
> logs; or at least I did. I don't know what has changed but elasticsearch is  
> now bailing on my timestamp field and is not able to correctly parse it.
> 
> I'm using logstash standard grok patterns (COMBINEDAPACHELOG in this case)
> 
> Is anyone able to assist me? I'm sure this is a simple fix?!
> 
> Please see below an example from my elasticsearch log
> 
> [2013-11-25 09:49:47,585][DEBUG][action.bulk] [Slade,  
> Hamilton] [logstash-2013.11.25][3] failed to execute bulk item (index)  
> index {[logstash-2013.11.25][logs][CxGMkA9nSjej7jHdNfXh4g],  
> source[{"message":"10.80.5.30 - - [25/Nov/2013:09:49:45 +0100] "GET  
> /examplerequest HTTP/1.1" 200 11415 "-" "Jakarta  
> Commons-HttpClient/3.1"","@timestamp":"2013-11-25T08:49:47.548Z","@version":"1","type":"webfrontend","file":"/var/loghttpdssl\_access\_log","host":"  
> [example.com](http://example.com)","offset":"629386952","clientip":"10.80.5.30","ident":"-","auth":"-","timestamp":"25/Nov/2013:09:49:45  
> +0100","verb":"GET","request":"/examplerequest","httpversion":"1.1","response":"200","bytes":"11415","referrer":""-"","agent":""Jakarta  
> Commons-HttpClient/3.1"","tags":["apache"]}]}  
> org.elasticsearch.index.mapper.MapperParsingException: failed to parse  
> [timestamp]  
> at  
> org.elasticsearch.index.mapper.core.AbstractFieldMapper.parse(AbstractFieldMapper.java:398)  
> at  
> org.elasticsearch.index.mapper.object.ObjectMapper.serializeValue(ObjectMapper.java:618)  
> at  
> org.elasticsearch.index.mapper.object.ObjectMapper.parse(ObjectMapper.java:471)  
> at  
> org.elasticsearch.index.mapper.DocumentMapper.parse(DocumentMapper.java:513)  
> at  
> org.elasticsearch.index.mapper.DocumentMapper.parse(DocumentMapper.java:457)  
> at  
> org.elasticsearch.index.shard.service.InternalIndexShard.prepareCreate(InternalIndexShard.java:342)  
> at  
> org.elasticsearch.action.bulk.TransportShardBulkAction.shardIndexOperation(TransportShardBulkAction.java:401)  
> at  
> org.elasticsearch.action.bulk.TransportShardBulkAction.shardOperationOnPrimary(TransportShardBulkAction.java:155)  
> at  
> org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction.performOnPrimary(TransportShardReplicationOperationAction.java:556)  
> at  
> org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction$1.run(TransportShardReplicationOperationAction.java:426)  
> at  
> java.util.concurrent.ThreadPoolExecutor$Worker.runTask(ThreadPoolExecutor.java:895)  
> at  
> java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:918)  
> at java.lang.Thread.run(Thread.java:662)  
> Caused by: org.elasticsearch.index.mapper.MapperParsingException: failed  
> to parse date field [25/Nov/2013:09:49:45 +0100], tried both date format  
> [dateOptionalTime], and timestamp number with locale   
> at  
> org.elasticsearch.index.mapper.core.DateFieldMapper.parseStringValue(DateFieldMapper.java:486)  
> at  
> org.elasticsearch.index.mapper.core.DateFieldMapper.innerParseCreateField(DateFieldMapper.java:424)  
> at  
> org.elasticsearch.index.mapper.core.NumberFieldMapper.parseCreateField(NumberFieldMapper.java:188)  
> at  
> org.elasticsearch.index.mapper.core.AbstractFieldMapper.parse(AbstractFieldMapper.java:387)  
> ... 12 more  
> Caused by: java.lang.IllegalArgumentException: Invalid format:  
> "25/Nov/2013:09:49:45 +0100" is malformed at "/Nov/2013:09:49:45 +0100"  
> at  
> org.elasticsearch.common.joda.time.format.DateTimeFormatter.parseMillis(DateTimeFormatter.java:754)  
> at  
> org.elasticsearch.index.mapper.core.DateFieldMapper.parseStringValue(DateFieldMapper.java:480)  
> ... 15 more
> 
> Thanks in advance!
> 
> Cheers,
> 
> Ben

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/519c7a1a-ac51-46a8-8d02-88291da9b1be%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/519c7a1a-ac51-46a8-8d02-88291da9b1be%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Ben\_Morrice](https://avatars.discourse-cdn.com/v4/letter/b/a8b319/32.png) [@Ben\_Morrice](https://discuss.elastic.co/u/Ben_Morrice)\
**Post date:** [December 12, 2013, 9:29am UTC](https://discuss.elastic.co/t/having-troubles-parsing-dates/14573/3 "2013-12-12T09:29:00Z")

</div>

Hi Phil,

Unfortunately i'm still seeing the same issue. Like your case this issue  
comes and goes as well. I am running a 2 node cluster (ES 0.90.7) with  
default configuration. I'm using logstash-1.2.2; however looking at the  
debug logs within logstash the events are parsed correctly, they just die  
when elasticsearch takes the floor.

Sorry I can't be of any more help... If you have any theories, please share  
your thoughts.

Cheers,

Ben

On Wednesday, 11 December 2013 21:26:41 UTC+1, Phil Dougherty wrote:

> I'm having the same exact issue. Running on a 4 node cluster and using ES  
> 0.90.3. Strangely this issue will randomly bite me, and it seems like it  
> happens when the index is living on a certain server. Were you able to  
> resolve this issue or could you provide some more information that may help  
> me resolve this?
> 
> On Monday, November 25, 2013 5:36:41 AM UTC-5, Ben Morrice wrote:
> 
> > Hello,
> > 
> > I have a basic logstash -\> elasticsearch instance running to parse apache  
> > logs; or at least I did. I don't know what has changed but elasticsearch is  
> > now bailing on my timestamp field and is not able to correctly parse it.
> > 
> > I'm using logstash standard grok patterns (COMBINEDAPACHELOG in this  
> > case)
> > 
> > Is anyone able to assist me? I'm sure this is a simple fix?!
> > 
> > Please see below an example from my elasticsearch log
> > 
> > [2013-11-25 09:49:47,585][DEBUG][action.bulk] [Slade,  
> > Hamilton] [logstash-2013.11.25][3] failed to execute bulk item (index)  
> > index {[logstash-2013.11.25][logs][CxGMkA9nSjej7jHdNfXh4g],  
> > source[{"message":"10.80.5.30 - - [25/Nov/2013:09:49:45 +0100] "GET  
> > /examplerequest HTTP/1.1" 200 11415 "-" "Jakarta  
> > Commons-HttpClient/3.1"","@timestamp":"2013-11-25T08:49:47.548Z","@version":"1","type":"webfrontend","file":"/var/loghttpdssl\_access\_log","host":"  
> > [example.com](http://example.com)","offset":"629386952","clientip":"10.80.5.30","ident":"-","auth":"-","timestamp":"25/Nov/2013:09:49:45  
> > +0100","verb":"GET","request":"/examplerequest","httpversion":"1.1","response":"200","bytes":"11415","referrer":""-"","agent":""Jakarta  
> > Commons-HttpClient/3.1"","tags":["apache"]}]}  
> > org.elasticsearch.index.mapper.MapperParsingException: failed to parse  
> > [timestamp]  
> > at  
> > org.elasticsearch.index.mapper.core.AbstractFieldMapper.parse(AbstractFieldMapper.java:398)  
> > at  
> > org.elasticsearch.index.mapper.object.ObjectMapper.serializeValue(ObjectMapper.java:618)  
> > at  
> > org.elasticsearch.index.mapper.object.ObjectMapper.parse(ObjectMapper.java:471)  
> > at  
> > org.elasticsearch.index.mapper.DocumentMapper.parse(DocumentMapper.java:513)  
> > at  
> > org.elasticsearch.index.mapper.DocumentMapper.parse(DocumentMapper.java:457)  
> > at  
> > org.elasticsearch.index.shard.service.InternalIndexShard.prepareCreate(InternalIndexShard.java:342)  
> > at  
> > org.elasticsearch.action.bulk.TransportShardBulkAction.shardIndexOperation(TransportShardBulkAction.java:401)  
> > at  
> > org.elasticsearch.action.bulk.TransportShardBulkAction.shardOperationOnPrimary(TransportShardBulkAction.java:155)  
> > at  
> > org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction.performOnPrimary(TransportShardReplicationOperationAction.java:556)  
> > at  
> > org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction$1.run(TransportShardReplicationOperationAction.java:426)  
> > at  
> > java.util.concurrent.ThreadPoolExecutor$Worker.runTask(ThreadPoolExecutor.java:895)  
> > at  
> > java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:918)  
> > at java.lang.Thread.run(Thread.java:662)  
> > Caused by: org.elasticsearch.index.mapper.MapperParsingException: failed  
> > to parse date field [25/Nov/2013:09:49:45 +0100], tried both date format  
> > [dateOptionalTime], and timestamp number with locale   
> > at  
> > org.elasticsearch.index.mapper.core.DateFieldMapper.parseStringValue(DateFieldMapper.java:486)  
> > at  
> > org.elasticsearch.index.mapper.core.DateFieldMapper.innerParseCreateField(DateFieldMapper.java:424)  
> > at  
> > org.elasticsearch.index.mapper.core.NumberFieldMapper.parseCreateField(NumberFieldMapper.java:188)  
> > at  
> > org.elasticsearch.index.mapper.core.AbstractFieldMapper.parse(AbstractFieldMapper.java:387)  
> > ... 12 more  
> > Caused by: java.lang.IllegalArgumentException: Invalid format:  
> > "25/Nov/2013:09:49:45 +0100" is malformed at "/Nov/2013:09:49:45 +0100"  
> > at  
> > org.elasticsearch.common.joda.time.format.DateTimeFormatter.parseMillis(DateTimeFormatter.java:754)  
> > at  
> > org.elasticsearch.index.mapper.core.DateFieldMapper.parseStringValue(DateFieldMapper.java:480)  
> > ... 15 more
> > 
> > Thanks in advance!
> > 
> > Cheers,
> > 
> > Ben

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/087f7e84-261c-4bde-b214-9be3580edae1%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/087f7e84-261c-4bde-b214-9be3580edae1%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 12, 2013, 10:01am UTC](https://discuss.elastic.co/t/having-troubles-parsing-dates/14573/4 "2013-12-12T10:01:29Z")

</div>

Hey,

judging from a quick peek at the problem: The value you are trying to parse  
as the timestamp field (note: not the logstash @timestamp field) is an  
unknown date format. This means it will only happen with apache access  
logs. Somehow the timestamp field has already been configured to be of a  
different format (from a past log entry most likely).

Two possibilites (note: maybe there are others, I am not a logstash wizard)

- Make the timestamp field a string and do not analyze it (which also  
means, you cannot search for it, but usually you are using the @timestamp  
field for that anyway)
- Have an own type for the apache access logs in your logstash config,  
which uses a special timestamp based mapping format, that fits to CLF  
timestamps

See

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

--Alex

On Thu, Dec 12, 2013 at 10:29 AM, Ben Morrice [ben.morrice@gmail.com](mailto:ben.morrice@gmail.com) wrote:

> Hi Phil,
> 
> Unfortunately i'm still seeing the same issue. Like your case this issue  
> comes and goes as well. I am running a 2 node cluster (ES 0.90.7) with  
> default configuration. I'm using logstash-1.2.2; however looking at the  
> debug logs within logstash the events are parsed correctly, they just die  
> when elasticsearch takes the floor.
> 
> Sorry I can't be of any more help... If you have any theories, please  
> share your thoughts.
> 
> Cheers,
> 
> Ben
> 
> On Wednesday, 11 December 2013 21:26:41 UTC+1, Phil Dougherty wrote:
> 
> > I'm having the same exact issue. Running on a 4 node cluster and using ES  
> > 0.90.3. Strangely this issue will randomly bite me, and it seems like it  
> > happens when the index is living on a certain server. Were you able to  
> > resolve this issue or could you provide some more information that may help  
> > me resolve this?
> > 
> > On Monday, November 25, 2013 5:36:41 AM UTC-5, Ben Morrice wrote:
> > 
> > > Hello,
> > > 
> > > I have a basic logstash -\> elasticsearch instance running to parse  
> > > apache logs; or at least I did. I don't know what has changed but  
> > > elasticsearch is now bailing on my timestamp field and is not able to  
> > > correctly parse it.
> > > 
> > > I'm using logstash standard grok patterns (COMBINEDAPACHELOG in this  
> > > case)
> > > 
> > > Is anyone able to assist me? I'm sure this is a simple fix?!
> > > 
> > > Please see below an example from my elasticsearch log
> > > 
> > > [2013-11-25 09:49:47,585][DEBUG][action.bulk] [Slade,  
> > > Hamilton] [logstash-2013.11.25][3] failed to execute bulk item (index)  
> > > index {[logstash-2013.11.25][logs][CxGMkA9nSjej7jHdNfXh4g],  
> > > source[{"message":"10.80.5.30 - - [25/Nov/2013:09:49:45 +0100] "GET  
> > > /examplerequest HTTP/1.1" 200 11415 "-" "Jakarta  
> > > Commons-HttpClient/3.1"","@timestamp":"2013-11-25T08:49:  
> > > 47.548Z","@version":"1","type":"webfrontend","file":"/var/  
> > > loghttpdssl\_access\_log","host":"[example.com](http://example.com)","offset":"  
> > > 629386952","clientip":"10.80.5.30","ident":"-","auth":"-","  
> > > timestamp":"25/Nov/2013:09:49:45 +0100","verb":"GET","request":  
> > > "/examplerequest","httpversion":"1.1","response":"200","bytes":"11415","  
> > > referrer":""-"","agent":""Jakarta Commons-HttpClient/3.1"","  
> > > tags":["apache"]}]}  
> > > org.elasticsearch.index.mapper.MapperParsingException: failed to parse  
> > > [timestamp]  
> > > at org.elasticsearch.index.mapper.core.AbstractFieldMapper.parse(  
> > > AbstractFieldMapper.java:398)  
> > > at org.elasticsearch.index.mapper.object.ObjectMapper.  
> > > serializeValue(ObjectMapper.java:618)  
> > > at org.elasticsearch.index.mapper.object.ObjectMapper.  
> > > parse(ObjectMapper.java:471)  
> > > at org.elasticsearch.index.mapper.DocumentMapper.parse(  
> > > DocumentMapper.java:513)  
> > > at org.elasticsearch.index.mapper.DocumentMapper.parse(  
> > > DocumentMapper.java:457)  
> > > at org.elasticsearch.index.shard.service.InternalIndexShard.  
> > > prepareCreate(InternalIndexShard.java:342)  
> > > at org.elasticsearch.action.bulk.TransportShardBulkAction.  
> > > shardIndexOperation(TransportShardBulkAction.java:401)  
> > > at org.elasticsearch.action.bulk.TransportShardBulkAction.  
> > > shardOperationOnPrimary(TransportShardBulkAction.java:155)  
> > > at org.elasticsearch.action.support.replication.  
> > > TransportShardReplicationOperationAction$AsyncShardOperationAction.  
> > > performOnPrimary(TransportShardReplicationOperationAction.java:556)  
> > > at org.elasticsearch.action.support.replication.  
> > > TransportShardReplicationOperationAction$AsyncShardOperationAction$1.  
> > > run(TransportShardReplicationOperationAction.java:426)  
> > > at java.util.concurrent.ThreadPoolExecutor$Worker.  
> > > runTask(ThreadPoolExecutor.java:895)  
> > > at java.util.concurrent.ThreadPoolExecutor$Worker.run(  
> > > ThreadPoolExecutor.java:918)  
> > > at java.lang.Thread.run(Thread.java:662)  
> > > Caused by: org.elasticsearch.index.mapper.MapperParsingException:  
> > > failed to parse date field [25/Nov/2013:09:49:45 +0100], tried both date  
> > > format [dateOptionalTime], and timestamp number with locale   
> > > at org.elasticsearch.index.mapper.core.DateFieldMapper.parseStringValue(  
> > > DateFieldMapper.java:486)  
> > > at org.elasticsearch.index.mapper.core.DateFieldMapper.  
> > > innerParseCreateField(DateFieldMapper.java:424)  
> > > at org.elasticsearch.index.mapper.core.NumberFieldMapper.  
> > > parseCreateField(NumberFieldMapper.java:188)  
> > > at org.elasticsearch.index.mapper.core.AbstractFieldMapper.parse(  
> > > AbstractFieldMapper.java:387)  
> > > ... 12 more  
> > > Caused by: java.lang.IllegalArgumentException: Invalid format:  
> > > "25/Nov/2013:09:49:45 +0100" is malformed at "/Nov/2013:09:49:45 +0100"  
> > > at org.elasticsearch.common.joda.time.format.DateTimeFormatter.  
> > > parseMillis(DateTimeFormatter.java:754)  
> > > at org.elasticsearch.index.mapper.core.DateFieldMapper.parseStringValue(  
> > > DateFieldMapper.java:480)  
> > > ... 15 more
> > > 
> > > Thanks in advance!
> > > 
> > > Cheers,
> > > 
> > > Ben
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google Groups  
> > > "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send an  
> > > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > > To view this discussion on the web visit  
> > > [https://groups.google.com/d/msgid/elasticsearch/087f7e84-261c-4bde-b214-9be3580edae1%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/087f7e84-261c-4bde-b214-9be3580edae1%40googlegroups.com)  
> > > .
> 
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAGCwEM\_eOC8rpT82U\_4AQ3GNX93BWvRPZkP9oe1j1q0unRu\_BA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAGCwEM_eOC8rpT82U_4AQ3GNX93BWvRPZkP9oe1j1q0unRu_BA%40mail.gmail.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:01am UTC](https://discuss.elastic.co/t/having-troubles-parsing-dates/14573/5 "2017-07-06T02:01:42Z")

</div>


