# How to parse two timestamp fields from one single log line message

**URL:** https://discuss.elastic.co/t/how-to-parse-two-timestamp-fields-from-one-single-log-line-message/286282
**Category:** Logstash
**Created:** [October 8, 2021, 10:55pm UTC](https://discuss.elastic.co/t/how-to-parse-two-timestamp-fields-from-one-single-log-line-message/286282 "2021-10-08T22:55:43Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![Patr123](https://avatars.discourse-cdn.com/v4/letter/p/ac91a4/32.png) [@Patr123](https://discuss.elastic.co/u/Patr123)
#### Post date: [October 8, 2021, 10:55pm UTC](https://discuss.elastic.co/t/how-to-parse-two-timestamp-fields-from-one-single-log-line-message/286282/1 "2021-10-08T22:55:43Z")

</div>

Hello All,  
I have log lines coming from K8's to logstash and they have two timestamps back to back. How can I parse those fields in let's say @timestamp field and timestamp2 field?

My log lines look like:

```auto
2021-10-08 18:39:09.866 EDT 2021-10-08 18:39:09.866 [http-nio-8443] [] Filter - CorrelationFilter Start

```

my logstash filter looks like:

```auto
filter {
                    multiline {
                        pattern => "^\[0-9]{4}-[0-9]{2}"
                        what => "previous"
                        negate=> true
                    }
                    grok {###Not sure how to write the grok for the second timestamp
			            match => ["message", "%{DATESTAMP:timestamp}"]
                    }
                    date {
                        match => ["timestamp", "yyyy-MM-dd H:m:s.SSS"]
                        target => ["@timestamp"]
                        remove_field => ["timestamp"]
                    }
                    mutate {
                        add_field => { "type" => "K8logs" }
                           }
            }

```

I am having difficulties in writing the grok for the second timestamp filter.  
Any help is appreciated.

Thank you.

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [October 9, 2021, 12:34am UTC](https://discuss.elastic.co/t/how-to-parse-two-timestamp-fields-from-one-single-log-line-message/286282/2 "2021-10-09T00:34:08Z")

</div>

I would do that using dissect

```
dissect { mapping => { "message" => "%{ts1} %{+ts1} %{+ts1} %{ts2} %{+ts2}" } }
mutate { gsub => ["ts1", "EDT", "EST5EDT"] }
date { match => ["ts1", "YYYY-MM-dd HH:mm:ss.SSS ZZZ"] target => "ts1" }
date { match => ["ts2", "YYYY-MM-dd HH:mm:ss.SSS"] target => "ts2" }

```

Joda does not support the ambiguous EDT timezone name, so you will need to gsub it to a non-ambiguous name.

---

<div class="post-metadata">

### Author: ![Patr123](https://avatars.discourse-cdn.com/v4/letter/p/ac91a4/32.png) [@Patr123](https://discuss.elastic.co/u/Patr123)
#### Post date: [October 9, 2021, 1:19am UTC](https://discuss.elastic.co/t/how-to-parse-two-timestamp-fields-from-one-single-log-line-message/286282/3 "2021-10-09T01:19:01Z")

</div>

> [@Patr123](#):
>
> ```auto
> [http-nio-8443] [] Filter - CorrelationFilter Start
> 
> ```

Thank you Badger.  
But then how will I grok filter should be?  
Something like this:

```auto
grok {
	   match => ["message", "\s\[%{DATA:threadid}\]\s\[\]\s%{WORD:filter}\s-\s%{GREEDYDATA:details}"]
      }

```

Is this correct? I mean I don't need to specify anything for the two timestamps in grok right?

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [October 9, 2021, 1:42am UTC](https://discuss.elastic.co/t/how-to-parse-two-timestamp-fields-from-one-single-log-line-message/286282/4 "2021-10-09T01:42:22Z")

</div>

> [@Patr123](#):
>
> But then how will I grok filter should be?

I am suggesting you use dissect and not use grok.

---

<div class="post-metadata">

### Author: ![Patr123](https://avatars.discourse-cdn.com/v4/letter/p/ac91a4/32.png) [@Patr123](https://discuss.elastic.co/u/Patr123)
#### Post date: [October 9, 2021, 1:52am UTC](https://discuss.elastic.co/t/how-to-parse-two-timestamp-fields-from-one-single-log-line-message/286282/5 "2021-10-09T01:52:58Z")

</div>

> [@Patr123](#):
>
> ilter shoul

Ok so something like this?

```auto
dissect { mapping => { "message" => "%{ts1} %{+ts1} %{+ts1} %{ts2} %{+ts2} [%{threadid}] [] %{filter} - %{details}" } }
mutate { gsub => ["ts1", "EDT", "EST5EDT"] }
date { match => ["ts1", "YYYY-MM-dd HH:mm:ss.SSS ZZZ"] target => "ts1" }
date { match => ["ts2", "YYYY-MM-dd HH:mm:ss.SSS"] target => "ts2" }

```

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [October 9, 2021, 2:14am UTC](https://discuss.elastic.co/t/how-to-parse-two-timestamp-fields-from-one-single-log-line-message/286282/6 "2021-10-09T02:14:35Z")

</div>

That looks reasonable.

---

<div class="post-metadata">

### Author: ![Patr123](https://avatars.discourse-cdn.com/v4/letter/p/ac91a4/32.png) [@Patr123](https://discuss.elastic.co/u/Patr123)
#### Post date: [October 10, 2021, 3:33pm UTC](https://discuss.elastic.co/t/how-to-parse-two-timestamp-fields-from-one-single-log-line-message/286282/7 "2021-10-10T15:33:30Z")

</div>

Thank you Badger, the steps you mentioned worked.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 7, 2021, 3:34pm UTC](https://discuss.elastic.co/t/how-to-parse-two-timestamp-fields-from-one-single-log-line-message/286282/8 "2021-11-07T15:34:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
