# How to parse date field into @timestamp

**URL:** <https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/351058>\
**Category:** Logstash\
**Created:** [January 15, 2024, 9:33am UTC](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/351058 "2024-01-15T09:33:50Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![emoxam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emoxam/32/125661_2.png) [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Post date:** [January 15, 2024, 9:33am UTC](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/351058/1 "2024-01-15T09:33:50Z")

</div>

i receive the spring app logs and i want to parse time from logs to @timestamp

that's what i got but timestamp is not the same.

> input {  
> tcp {  
> port =\> 5000  
> codec =\>plain  
> }  
> }
> 
> filter {  
> if [message] =~ /actions/ {  
> grok {  
> match =\> [ "message",  
> "%{GREEDYDATA:timestamp} %{LOGLEVEL:level} %{GREEDYDATA:data}"  
> ]  
> }  
> date {  
> match =\> ["timestamp" , "yyyy-MM-dd HH:mm:ss.SSS"]  
> }  
> }  
> }

What am i doing wrong ?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 15, 2024, 9:44am UTC](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/351058/2 "2024-01-15T09:44:44Z")

</div>

Can you show us how does a full message look like?

---

<div class="post-metadata">

**Author:** ![emoxam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emoxam/32/125661_2.png) [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Post date:** [January 16, 2024, 12:49pm UTC](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/351058/3 "2024-01-16T12:49:54Z")

</div>

Sorry i forgot the main string

target =\> "@timestamp"

P.S. To be clear tha part of config should be

> date {  
> match =\> ["timestamp" , "yyyy-MM-dd HH:mm:ss,SSS"]  
> target =\> "@timestamp"  
> }

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 16, 2024, 12:55pm UTC](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/351058/4 "2024-01-16T12:55:58Z")

</div>

You need to share how your source message looks like, there is nothing wrong in the `date` filter, you also does not need to specify the target if the target is the `@timestamp` field, this is the default.

If your date filter is not work, so something is wrong with the value of your `timestamp` field, which could indicate something wrong with your parsing.

You need to share a sample of a message that you are receiving and trying to parse.

---

<div class="post-metadata">

**Author:** ![emoxam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emoxam/32/125661_2.png) [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Post date:** [January 16, 2024, 5:46pm UTC](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/351058/5 "2024-01-16T17:46:06Z")

</div>

> 2024-01-16 20:45:31.293 DEBUG [actions,,] 8 --- [/api/v2/spans}}] o.s.w.HttpLogging : HTTP POST [http://172.16.10.78:9411/api/v2/spans](http://172.16.10.78:9411/api/v2/spans)  
> 2024-01-16 20:45:31.293 DEBUG [actions,,] 8 --- [/api/v2/spans}}] o.s.w.HttpLogging : Accept=[text/plain, application/json, application/\*+json, _/_]  
> 2024-01-16 20:45:31.294 DEBUG [actions,,] 8 --- [/api/v2/spans}}] o.s.w.HttpLogging : Writing [[B@5d1ee735] as "application/json"  
> 2024-01-16 20:45:31.295 DEBUG [actions,,] 8 --- [/api/v2/spans}}] o.s.w.HttpLogging : Response 202 ACCEPTED  
> 2024-01-16 20:45:40.001 INFO [actions,,] 8 --- [scheduling-1] r.i.d.a.s.DeviceQueueExecutor : =========== runner start ===========  
> 2024-01-16 20:45:40.046 DEBUG [actions,,] 8 --- [scheduling-1] o.s.w.r.f.c.ExchangeFunctions : [25d86162] HTTP GET [http://172.16.10.77:8001/?device=module&action=getStatus](http://172.16.10.77:8001/?device=module&action=getStatus)  
> 2024-01-16 20:45:40.048 DEBUG [actions,,] 8 --- [or-http-epoll-4] o.s.w.r.f.c.ExchangeFunctions : [25d86162] [4bc96d38-1, L:/192.168.190.58:36332 - R:172.16.10.77/172.16.10.77:8001] Response 200 OK

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 16, 2024, 6:41pm UTC](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/351058/6 "2024-01-16T18:41:07Z")

</div>

> [@emoxam](#):
>
> 2024-01-16 20:45:31.293

The timestamp in your log has the format `yyyy-MM-dd HH:mm:ss.SSS`, but in your `date` filter you have `yyyy-MM-dd HH:mm:ss,SSS`.

The separator between seconds and miliseconds is not correct in your `date` filter.

---

<div class="post-metadata">

**Author:** ![emoxam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emoxam/32/125661_2.png) [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Post date:** [January 16, 2024, 6:54pm UTC](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/351058/7 "2024-01-16T18:54:09Z")

</div>

You are right! Thank! My fault!

The right part is

> date {  
> match =\> ["timestamp" , "yyyy-MM-dd HH:mm:ss.SSS"]
> 
> # target =\> "@timestamp"
> 
> }

---

<div class="post-metadata">

**Author:** ![emoxam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emoxam/32/125661_2.png) [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Post date:** [January 17, 2024, 6:46am UTC](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/351058/8 "2024-01-17T06:46:05Z")

</div>

I wanted to show that string  
target =\> "@timestamp"  
is commented, but # makes it bigger))

---

<div class="post-metadata">

**Author:** ![emoxam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emoxam/32/125661_2.png) [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Post date:** [January 17, 2024, 8:01am UTC](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/351058/9 "2024-01-17T08:01:39Z")

</div>

From the kubernetes pod console i se there is

> .

But at the

> journalctl -o cat -xefu logstash.service

i see there is

> ,

why is it so ?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 17, 2024, 12:10pm UTC](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/351058/10 "2024-01-17T12:10:13Z")

</div>

> [@emoxam](#):
>
> journalctl -o cat -xefu logstash.service

This will show the logs from your logstash service, it is unrelated to the logs of your application that you are parsing.

The timestamp in logstash logs uses `,` between the seconds and miliseconds.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2024, 12:10pm UTC](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/351058/11 "2024-02-14T12:10:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
