# How to remove date and time in message

**URL:** <https://discuss.elastic.co/t/how-to-remove-date-and-time-in-message/294280>\
**Category:** Logstash\
**Created:** [January 13, 2022, 1:42pm UTC](https://discuss.elastic.co/t/how-to-remove-date-and-time-in-message/294280 "2022-01-13T13:42:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Roccof97](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roccof97/32/97628_2.png) [@Roccof97](https://discuss.elastic.co/u/Roccof97)\
**Post date:** [January 13, 2022, 1:42pm UTC](https://discuss.elastic.co/t/how-to-remove-date-and-time-in-message/294280/1 "2022-01-13T13:42:52Z")

</div>

Hi,

how can i remove the date and time from the message field? and above all is it possible?  
example screen shot:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/d/ddf7aa5d55b08db88cc84bf7f98abd9487b7e0de.png)

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [January 13, 2022, 2:38pm UTC](https://discuss.elastic.co/t/how-to-remove-date-and-time-in-message/294280/2 "2022-01-13T14:38:57Z")

</div>

I suppose it is possible using [grok filter plugin](https://www.elastic.co/guide/en/logstash/7.16/plugins-filters-grok.html) with logstash while ingestion.

---

<div class="post-metadata">

**Author:** ![Roccof97](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roccof97/32/97628_2.png) [@Roccof97](https://discuss.elastic.co/u/Roccof97)\
**Post date:** [January 13, 2022, 2:45pm UTC](https://discuss.elastic.co/t/how-to-remove-date-and-time-in-message/294280/3 "2022-01-13T14:45:35Z")

</div>

i'm already using the grock filter but i can't figure out how to remove the date from the message i tried the gsub function but i didn't succeed here is the example:

if [fields][log\_type] == "maillog" {  
grok {  
break\_on\_match =\> false  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:timestamp}" }  
}  
date { match =\> ["timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
mutate {

> ```
> gsub => ["message", "\d{3} \d{2} \d{2}:\d{2}:\d{2}", ""]
> 
> ```

}

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 13, 2022, 2:59pm UTC](https://discuss.elastic.co/t/how-to-remove-date-and-time-in-message/294280/4 "2022-01-13T14:59:56Z")

</div>

You can use the dissect filter to parse your original message field and override it with everything else except the date.

```auto
     dissect {
         mapping => {
             "message" => "%{} %{} %{}:%{}:%{} %{message}"
         }
     }

```

This will transform any message with the format:

```auto
MMM dd HH:mm:ss some text from your message

```

Into

```auto
some text from your message

```

For example, `Jan 13 14:59:30 sample text` will become `sample text`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 10, 2022, 3:00pm UTC](https://discuss.elastic.co/t/how-to-remove-date-and-time-in-message/294280/5 "2022-02-10T15:00:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
