# How can I parse this date format into @timestamp?

**URL:** <https://discuss.elastic.co/t/how-can-i-parse-this-date-format-into-timestamp/316261>\
**Category:** Logstash\
**Created:** [October 11, 2022, 3:01am UTC](https://discuss.elastic.co/t/how-can-i-parse-this-date-format-into-timestamp/316261 "2022-10-11T03:01:24Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Roger\_Huang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roger_huang/32/106867_2.png) [@Roger\_Huang](https://discuss.elastic.co/u/Roger_Huang)\
**Post date:** [October 11, 2022, 3:01am UTC](https://discuss.elastic.co/t/how-can-i-parse-this-date-format-into-timestamp/316261/1 "2022-10-11T03:01:24Z")

</div>

Hi everyone, I am new to ELK and I cannot seems to get this right. Keep getting date parse error. I also wanted to put the \_time to @timestamp.

For your kind advise please.

 ![Screenshot 2022-10-11 at 10.59.56 AM](https://us1.discourse-cdn.com/elastic/original/3X/e/b/eba4bf5c22771e918e17eae7ab726d7bc7ed67b3.png)

```auto
2022-06-30T13:14:40.558

```

Edgar.conf

```auto
input {
	file {
		path => "/usr/share/logstash/elogs/log20220630.csv"
		start_position => "beginning"
        sincedb_path => "/dev/null"
	}
}

filter {
	csv {
		separator => ","
		skip_header => "true"
		columns => ["_time","uri_path"]
	}
	date {
	    match => ["_time", "YYYY-MM-dd HH:mm:ss.SSS"]
	    target => "@timestamp"
        add_field => { "debug" => "timestampMatched"}
	}
}
output {
	elasticsearch {
		hosts => "elasticsearch:9200"
		user => "logstash_internal"
		password => "${LOGSTASH_INTERNAL_PASSWORD}"
		index => "ecs-logstash-edgar"
	}
	file {
        path => "/usr/share/logstash/elogs/output/edgar_log.txt"
    }
	stdout {}
}

```

 ![Screenshot 2022-10-11 at 10.58.54 AM](https://us1.discourse-cdn.com/elastic/original/3X/7/0/70513ddcde3967216585210c34dd5fecbfd7837d.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 11, 2022, 5:55am UTC](https://discuss.elastic.co/t/how-can-i-parse-this-date-format-into-timestamp/316261/2 "2022-10-11T05:55:30Z")

</div>

Hi @Roger_Huang Welcome to the community!

> [@Roger\_Huang](#):
>
> `match => ["_time", "YYYY-MM-dd HH:mm:ss.SSS"]`

Perhaps Your missing the `T`

`match => ["_time", "YYYY-MM-dd'T'HH:mm:ss.SSS"]`

`2022-06-30T13:14:40.558`

Corrected per @Rios

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 11, 2022, 6:31am UTC](https://discuss.elastic.co/t/how-can-i-parse-this-date-format-into-timestamp/316261/3 "2022-10-11T06:31:35Z")

</div>

You can use also ISO8601.

```auto
	date {
	    match => ["_time", "ISO8601"]
	    target => "@timestamp"
	    add_field => { "debug" => "timestampMatched"}
	}

```

---

<div class="post-metadata">

**Author:** ![Roger\_Huang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roger_huang/32/106867_2.png) [@Roger\_Huang](https://discuss.elastic.co/u/Roger_Huang)\
**Post date:** [October 11, 2022, 1:25pm UTC](https://discuss.elastic.co/t/how-can-i-parse-this-date-format-into-timestamp/316261/4 "2022-10-11T13:25:31Z")

</div>

Hi Stephen,

Thanks for sharing for using the "T". It does not work on the first instance, but will try again to find out why it doesn't tomorrow. For now, the "ISO8601" works for me.

---

<div class="post-metadata">

**Author:** ![Roger\_Huang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roger_huang/32/106867_2.png) [@Roger\_Huang](https://discuss.elastic.co/u/Roger_Huang)\
**Post date:** [October 11, 2022, 1:28pm UTC](https://discuss.elastic.co/t/how-can-i-parse-this-date-format-into-timestamp/316261/5 "2022-10-11T13:28:30Z")

</div>

Thanks all for your inputs. I have learned a lot from you guys. Cheers and will close this topic for now.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 20, 2022, 7:51pm UTC](https://discuss.elastic.co/t/how-can-i-parse-this-date-format-into-timestamp/316261/6 "2022-10-20T19:51:04Z")

</div>

Just for info, you can also use as you suggest with 'T' , instead of ISO8601:  
` match => ["_time", "YYYY-MM-dd'T'HH:mm:ss.SSS"]`

> For non-formatting syntax, you’ll need to put single-quote characters around the value. For example, if you were parsing ISO8601 time, "2015-01-01T01:12:23" that little "T" isn’t a valid time format, and you want to say "literally, a T", your format would be this: "yyyy-MM-dd’T’HH:mm:ss"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 17, 2022, 7:51pm UTC](https://discuss.elastic.co/t/how-can-i-parse-this-date-format-into-timestamp/316261/7 "2022-11-17T19:51:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
