# How to parse multiple date fields?

**URL:** <https://discuss.elastic.co/t/how-to-parse-multiple-date-fields/1208>\
**Category:** Logstash\
**Created:** [May 23, 2015, 5:22pm UTC](https://discuss.elastic.co/t/how-to-parse-multiple-date-fields/1208 "2015-05-23T17:22:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![pescobar](https://avatars.discourse-cdn.com/v4/letter/p/48db29/32.png) [@pescobar](https://discuss.elastic.co/u/pescobar)\
**Post date:** [May 23, 2015, 5:22pm UTC](https://discuss.elastic.co/t/how-to-parse-multiple-date-fields/1208/1 "2015-05-23T17:22:55Z")

</div>

Hi,

I am learning logstash to insert my logfiles in elasticsearch. By now I am testing this config file:  
input {

```
  file {
    type => "accounting"
    path => ["/root/logstash-tests/mini-test/accounting.txt"]
    start_position => "beginning"
        }
}

filter {
  if [type] == "accounting" {
    grok {
      match => { "message" => "%{DATA:qname}:%{DATA:exechost}:%{DATA:group}:%{DATA:owner}:%{DATA:job_name}:%{INT:jobid}:%{DATA:account}:%{INT:priority}:%{INT:submission_time}:%{INT:start_time}:%{INT:end_time}:%{INT:failed}:%{INT:exit_status}$" }
        }

   date {
        match => ["submission_time", "UNIX_MS"]
    target => "@timestamp"
        }

}
}

output {
        stdout {codec => rubydebug}
}

```

which gives me this output:

```
[root@logs-test mini-test]# /opt/logstash/bin/logstash agent -f test.conf
Logstash startup completed
{
            "message" => "gpu.q:pgi02.mydomain.com:group22:user22:arrayjob.sh:3511939:sge:0:1428589483565:1429783559251:1429785864500:0:0",
           "@version" => "1",
         "@timestamp" => "2015-04-09T14:24:43.565Z",
               "type" => "accounting",
               "host" => "logs-test",
               "path" => "/root/logstash-tests/mini-test/accounting.txt",
              "qname" => "gpu.q",
           "exechost" => "pgi02.mydomain.com",
              "group" => "group22",
              "owner" => "user22",
           "job_name" => "arrayjob.sh",
              "jobid" => "3511939",
            "account" => "sge",
           "priority" => "0",
    "submission_time" => "1428589483565",
         "start_time" => "1429783559251",
           "end_time" => "1429785864500",
             "failed" => "0",
        "exit_status" => "0"
}

```

the submission\_time field is being converted to a time type field to be used in @timestamp correctly by using the date filter but I have other two fields in format UNIX\_MS (start\_time and end\_time) which I would like to convert to date type fields when inserting to elasticsearch. How should I modify by config file so start\_time and end\_time are also date type fields in elasticsearch? Could you point to some example?

thanks in advance for your help.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 24, 2015, 2:17am UTC](https://discuss.elastic.co/t/how-to-parse-multiple-date-fields/1208/2 "2015-05-24T02:17:37Z")

</div>

You just want a few more date + match + target sections like you have for @timestamp, one per other field.

---

<div class="post-metadata">

**Author:** ![pescobar](https://avatars.discourse-cdn.com/v4/letter/p/48db29/32.png) [@pescobar](https://discuss.elastic.co/u/pescobar)\
**Post date:** [May 24, 2015, 10:00am UTC](https://discuss.elastic.co/t/how-to-parse-multiple-date-fields/1208/3 "2015-05-24T10:00:03Z")

</div>

thanks for your help warkolm. Now that I have it working it seems obvious 😄

for future reference in case anyone have this doubt in the future and reachs this post, this is my working config:

```
    date {
        match => ["submission_time", "UNIX_MS"]
        target => "@timestamp"
        }

   date {
        match => ["submission_time", "UNIX_MS"]
        target => "submission_time"
        }

   date {
        match => ["start_time", "UNIX_MS"]
        target => "start_time"
        }

   date {
        match => ["end_time", "UNIX_MS"]
        target => "end_time"
        }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:39am UTC](https://discuss.elastic.co/t/how-to-parse-multiple-date-fields/1208/4 "2017-07-06T05:39:25Z")

</div>


