# How to use date-filter-plugin?

**URL:** <https://discuss.elastic.co/t/how-to-use-date-filter-plugin/35054>\
**Category:** Logstash\
**Created:** [November 19, 2015, 1:08pm UTC](https://discuss.elastic.co/t/how-to-use-date-filter-plugin/35054 "2015-11-19T13:08:14Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alvin82](https://avatars.discourse-cdn.com/v4/letter/a/8edcca/32.png) [@Alvin82](https://discuss.elastic.co/u/Alvin82)\
**Post date:** [November 19, 2015, 1:08pm UTC](https://discuss.elastic.co/t/how-to-use-date-filter-plugin/35054/1 "2015-11-19T13:08:14Z")

</div>

I'm using date plugin, but i'm not able to match this timestamp

```
log_ts = 2015-11-19-11:14:23.8704

```

If i use this snippet code in the conf file

```
 date {
         match => ["log_ts", "yyyy-MM-dd-HH:mm:ss.SSSS"]
}

```

I obtain this exception

```
arsing_exception", "reason"=>"failed to parse [log_ts]", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"Invalid format: \"2015-11-19-11:14:23.8704\" is malformed at \"-11:14:23.8704\""}}}}, :level=>:warn, :file=>"logstash/outputs/elasticsearch.rb", :line=>"369", :method=>"submit"}

```

Why i have this error?How can i match that timestamp?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 19, 2015, 1:28pm UTC](https://discuss.elastic.co/t/how-to-use-date-filter-plugin/35054/2 "2015-11-19T13:28:11Z")

</div>

Works fine for me (Logstash 1.5.3):

```
$ cat test.config 
input { stdin { } }
output { stdout { codec => "rubydebug" } }
filter {
  date {
    match => ["message", "yyyy-MM-dd-HH:mm:ss.SSSS"]
  }
}
$ echo '2015-11-19-11:14:23.8704' | /opt/logstash/bin/logstash -f test.config
Logstash startup completed
{
       "message" => "2015-11-19-11:14:23.8704",
      "@version" => "1",
    "@timestamp" => "2015-11-19T10:14:23.870Z",
          "host" => "lnxolofon"
}
Logstash shutdown completed
```

---

<div class="post-metadata">

**Author:** ![pierre](https://avatars.discourse-cdn.com/v4/letter/p/d07c76/32.png) [@pierre](https://discuss.elastic.co/u/pierre)\
**Post date:** [December 15, 2016, 12:57pm UTC](https://discuss.elastic.co/t/how-to-use-date-filter-plugin/35054/3 "2016-12-15T12:57:30Z")

</div>

i have this :  
01-11-2015;17:41:01;641

filter {  
grok {  
break\_on\_match =\> "false"  
match =\> { "message" =\> '%{DATA}%{DATE\_EU:Date};%{TIME:Date};%{NUMBER:Nombre}%{DATA}'}  
}  
}  
but my date en heure = string  
i want date so i use

date {  
match =\> ["Date", "dd MM YYYY HH:mm:ss"]  
}

but i have  
{  
"\_index": "logstash-2016.12.15",  
"\_type": "Vmware",  
"\_id": "AVkCgGy96I\_tcz\_3yhMg",  
"\_score": null,  
"\_source": {  
"Nombre": 751,  
"path": "/var/log/StatVM/test10.log",  
"@timestamp": "2016-12-15T12:41:27.524Z",  
"@version": "1",  
"host": "localhost.localdomain",  
"message": "14-12-2016;11:20:01;751",  
"type": "Vmware",  
"Date": [  
"14-12-2016",  
"11:20:01"  
],  
"tags": [  
"\_dateparsefailure",  
"\_grokparsefailure"  
]  
},  
"fields": {  
"@timestamp": [  
1481805687524  
]  
},  
"sort": [  
1481805687524  
]  
}  
},  
"fields": {  
"@timestamp": [  
1481804404819  
]  
},  
"sort": [  
1481804404819  
]  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 15, 2016, 1:37pm UTC](https://discuss.elastic.co/t/how-to-use-date-filter-plugin/35054/4 "2016-12-15T13:37:09Z")

</div>

@pierre, please start a new thread for your unrelated question.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:29am UTC](https://discuss.elastic.co/t/how-to-use-date-filter-plugin/35054/5 "2017-07-06T04:29:50Z")

</div>


