# How can I use the date filter (match) with many fields

**URL:** <https://discuss.elastic.co/t/how-can-i-use-the-date-filter-match-with-many-fields/126457>\
**Category:** Logstash\
**Created:** [April 2, 2018, 6:59pm UTC](https://discuss.elastic.co/t/how-can-i-use-the-date-filter-match-with-many-fields/126457 "2018-04-02T18:59:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Daniel\_Gonzalez1](https://avatars.discourse-cdn.com/v4/letter/d/57b2e6/32.png) [@Daniel\_Gonzalez1](https://discuss.elastic.co/u/Daniel_Gonzalez1)\
**Post date:** [April 2, 2018, 6:59pm UTC](https://discuss.elastic.co/t/how-can-i-use-the-date-filter-match-with-many-fields/126457/1 "2018-04-02T18:59:21Z")

</div>

Hello!

I want to match the date from a cvs file that comes in different fields with logstash! The date in the cvs file come in four fields (four columns) for example:

|Fecha\_Trans|HH|MM|SS|  
180314 |16 | 40 |45|

I was trying to do this but only is working with the field "Fecha\_Trans" in the timestamp but is not recognizing the HH field, MM field and SS. ¿How Can I nest the fields?

date {  
match =\> ["Fecha\_Trans", "yyMMdd"]  
match =\> ["HH", "HH"]  
match =\> ["MM", "mm"]  
match =\> ["SS", "ss"]  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 2, 2018, 7:19pm UTC](https://discuss.elastic.co/t/how-can-i-use-the-date-filter-match-with-many-fields/126457/2 "2018-04-02T19:19:50Z")

</div>

The date filter parses a single field. If your timestamp is spread over multiple fields you'll have to combine them first. You can e.g. use a mutate filter for that.

---

<div class="post-metadata">

**Author:** ![Daniel\_Gonzalez1](https://avatars.discourse-cdn.com/v4/letter/d/57b2e6/32.png) [@Daniel\_Gonzalez1](https://discuss.elastic.co/u/Daniel_Gonzalez1)\
**Post date:** [April 2, 2018, 7:28pm UTC](https://discuss.elastic.co/t/how-can-i-use-the-date-filter-match-with-many-fields/126457/3 "2018-04-02T19:28:58Z")

</div>

Hello Magnusbaeck!

Thanks so much for your reply! I'm so sorry I'm new with this tool of logstash, do you have any suggestions of which type of mutate filter can I use?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 3, 2018, 9:57am UTC](https://discuss.elastic.co/t/how-can-i-use-the-date-filter-match-with-many-fields/126457/4 "2018-04-03T09:57:45Z")

</div>

> <https://stackoverflow.com/questions/28879131/how-to-generate-timestamp-in-logstash-by-combining-two-fields-columns-of-inpu>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 1, 2018, 9:57am UTC](https://discuss.elastic.co/t/how-can-i-use-the-date-filter-match-with-many-fields/126457/5 "2018-05-01T09:57:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
