# How to use ELK to extract data from specific dates from Date field in csv

**URL:** <https://discuss.elastic.co/t/how-to-use-elk-to-extract-data-from-specific-dates-from-date-field-in-csv/41623>\
**Category:** Kibana\
**Created:** [February 12, 2016, 2:43pm UTC](https://discuss.elastic.co/t/how-to-use-elk-to-extract-data-from-specific-dates-from-date-field-in-csv/41623 "2016-02-12T14:43:53Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![poornima](https://avatars.discourse-cdn.com/v4/letter/p/85f322/32.png) [@poornima](https://discuss.elastic.co/u/poornima)\
**Post date:** [February 12, 2016, 2:43pm UTC](https://discuss.elastic.co/t/how-to-use-elk-to-extract-data-from-specific-dates-from-date-field-in-csv/41623/1 "2016-02-12T14:43:53Z")

</div>

Hi all,  
Need help in creating dashboard for defects.  
I need to extract data based on date field column in a csv file and plot graphs based on it.  
I want X axis to be based on specific date range field from the csv file.

![](https://us1.discourse-cdn.com/elastic/original/2X/2/2965b3f6e9cbc1327f6dcfe8776d06ec5ad2fa76.png)

For example, in the attached csv file, I want the count of Severity - 1,2,3,4 and count of Regression that are within submit Date 11/1/2015 to 11/15/2015 and similarly within submit Date 11/16/2015 to 11/30/2015.

How can this be achieved in kibana?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 12, 2016, 2:55pm UTC](https://discuss.elastic.co/t/how-to-use-elk-to-extract-data-from-specific-dates-from-date-field-in-csv/41623/2 "2016-02-12T14:55:32Z")

</div>

So you don't have the data in Elasticsearch yet? Then use Logstash to parse the CSV file and its date field. You'll need something like this:

```auto
input {
  file {
    ...
  }
}
filter {
  csv {
    ...
  }
  date {
    ...
  }
}
output {
  elasticsearch {
    ...
  }
}

```

---

<div class="post-metadata">

**Author:** ![poornima](https://avatars.discourse-cdn.com/v4/letter/p/85f322/32.png) [@poornima](https://discuss.elastic.co/u/poornima)\
**Post date:** [February 15, 2016, 5:13am UTC](https://discuss.elastic.co/t/how-to-use-elk-to-extract-data-from-specific-dates-from-date-field-in-csv/41623/3 "2016-02-15T05:13:59Z")

</div>

Thanks for your inputs.

This is what I tried

date {  
match =\> ["submit date", "DD/MM/YYYY"]  
target =\> "@timestamp"  
}

![](https://us1.discourse-cdn.com/elastic/original/2X/a/af3bc2eaf452595580de693ea437c01fbada2fec.png)

But still am not able to get to use the "submit date" as "timestamp".

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 15, 2016, 6:34am UTC](https://discuss.elastic.co/t/how-to-use-elk-to-extract-data-from-specific-dates-from-date-field-in-csv/41623/4 "2016-02-15T06:34:35Z")

</div>

It looks like the field is named "Submit Date" so don't use "submit date" in your filter. Secondly, "DD" in date patterns means "day of year", not "day of month". Use "dd" instead. See the [Joda-Time documentation](http://joda-time.sourceforge.net/apidocs/org/joda/time/format/DateTimeFormat.html) for details.

The Logstash log usually contains useful information about date parsing problems.

---

<div class="post-metadata">

**Author:** ![poornima](https://avatars.discourse-cdn.com/v4/letter/p/85f322/32.png) [@poornima](https://discuss.elastic.co/u/poornima)\
**Post date:** [February 15, 2016, 6:47am UTC](https://discuss.elastic.co/t/how-to-use-elk-to-extract-data-from-specific-dates-from-date-field-in-csv/41623/5 "2016-02-15T06:47:03Z")

</div>

Thanks Magnus, as you suggested I have changed the date filter as below:

date {  
match =\> ["Submit Date", "MM/dd/yyyy"]  
target =\> "@timestamp"  
}

In stdout console, I am able to get "timestamp" mapped to "Submit Date" as below :

**2015-11-01T18:30:00.000Z POORNIMC-7RE9W 11/2/2015,N,,2,**  
**2015-11-04T18:30:00.000Z POORNIMC-7RE9W 11/5/2015,N,,2,**  
**2015-11-02T18:30:00.000Z POORNIMC-7RE9W 11/3/2015,N,,2,**  
**2015-11-04T18:30:00.000Z POORNIMC-7RE9W 11/5/2015,N,,2,**  
**2015-11-05T18:30:00.000Z POORNIMC-7RE9W 11/6/2015,N,Y,2,**  
**2015-11-05T18:30:00.000Z POORNIMC-7RE9W 11/6/2015,N,,1,Y**  
**2015-11-04T18:30:00.000Z POORNIMC-7RE9W 11/5/2015,N,,2,**  
**2015-11-06T18:30:00.000Z POORNIMC-7RE9W 11/7/2015,N,Y,1,Y**  
**2015-11-15T18:30:00.000Z POORNIMC-7RE9W 11/16/2015,N,,3,**  
**2015-11-16T18:30:00.000Z POORNIMC-7RE9W 11/17/2015,N,Y,2,**

But not able to see any updates in Kibana.  
Even tried deleting and creating new index but still the latest logs are not seen in kibana.  
Any inputs on how to proceed?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 15, 2016, 6:51am UTC](https://discuss.elastic.co/t/how-to-use-elk-to-extract-data-from-specific-dates-from-date-field-in-csv/41623/6 "2016-02-15T06:51:33Z")

</div>

Yeah, this looks good. Keep in mind that `@timestamp` is UTC (and you're obviously in UTC+5.30). To reparse an old file with Logstash, delete the sincedb file or set `sincedb_path` to /dev/null. See the file input documentation for details.

---

<div class="post-metadata">

**Author:** ![poornima](https://avatars.discourse-cdn.com/v4/letter/p/85f322/32.png) [@poornima](https://discuss.elastic.co/u/poornima)\
**Post date:** [February 16, 2016, 9:37am UTC](https://discuss.elastic.co/t/how-to-use-elk-to-extract-data-from-specific-dates-from-date-field-in-csv/41623/7 "2016-02-16T09:37:40Z")

</div>

Thanks Magnus 🙂

I am able to get the timestamp as expected in the console as below :

2015-11-02T00:00:00.000Z POORNIMC-7RE9W 11/2/2015,N,,2,  
2015-11-05T00:00:00.000Z POORNIMC-7RE9W 11/5/2015,N,,2,  
2015-11-05T00:00:00.000Z POORNIMC-7RE9W 11/5/2015,N,,2,  
2015-11-05T00:00:00.000Z POORNIMC-7RE9W 11/5/2015,N,,2,  
2015-11-06T00:00:00.000Z POORNIMC-7RE9W 11/6/2015,N,Y,2,  
2015-11-06T00:00:00.000Z POORNIMC-7RE9W 11/6/2015,N,,1,Y  
2015-11-03T00:00:00.000Z POORNIMC-7RE9W 11/3/2015,N,,2,  
2015-11-07T00:00:00.000Z POORNIMC-7RE9W 11/7/2015,N,,Others,Y  
2015-11-16T00:00:00.000Z POORNIMC-7RE9W 11/16/2015,N,,3,  
2015-11-17T00:00:00.000Z POORNIMC-7RE9W 11/17/2015,N,Y,2,

As you suggested, I routed sincedb path file and kibana worked.  
But in Kibana I see timestamp still does not refer to submit [date.Is](http://date.Is) there any other config change to be done in kibana?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 16, 2016, 9:39am UTC](https://discuss.elastic.co/t/how-to-use-elk-to-extract-data-from-specific-dates-from-date-field-in-csv/41623/8 "2016-02-16T09:39:41Z")

</div>

For a particular message,

- what's the original date,
- what's the raw value of the `@timestamp` field, and
- what's displayed in Kibana?

---

<div class="post-metadata">

**Author:** ![poornima](https://avatars.discourse-cdn.com/v4/letter/p/85f322/32.png) [@poornima](https://discuss.elastic.co/u/poornima)\
**Post date:** [February 16, 2016, 9:47am UTC](https://discuss.elastic.co/t/how-to-use-elk-to-extract-data-from-specific-dates-from-date-field-in-csv/41623/9 "2016-02-16T09:47:58Z")

</div>

what's the original date,  
**I am expecting the 'submit date' to appear in timestamp field- [Ex: 11/17/2015]**

what's the raw value of the @timestamp field, and

**@timestamp:February 16th 2016, 14:36:11.042**

what's displayed in Kibana?

**message:11/17/2015,N,,2, @version:1 @timestamp:February 16th 2016, 14:36:11.042 host:POORNIMC-7RE9W path:C:/ELK/logstash-2.1.1/logstash-2.1.1/bin/Test/Test.csv Submit Date:11/17/2015 Status:N Regression: - Severity:2 Customer-track-number: - \_id:AVLpVHARcKyJnxyGOLqG \_type:logs \_index:logstash-2016.02.47 \_score:**

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 16, 2016, 9:53am UTC](https://discuss.elastic.co/t/how-to-use-elk-to-extract-data-from-specific-dates-from-date-field-in-csv/41623/10 "2016-02-16T09:53:47Z")

</div>

> @timestamp:February 16th 2016, 14:36:11.042

That's _not_ the raw value. I expected something like "2016-02-16T...".

In your last post you said you got

```
2015-11-17T00:00:00.000Z POORNIMC-7RE9W 11/17/2015,N,Y,2,

```

in your console, which looks correct. If you're getting February instead of November in Kibana I suspect you're looking at the wrong events.

---

<div class="post-metadata">

**Author:** ![poornima](https://avatars.discourse-cdn.com/v4/letter/p/85f322/32.png) [@poornima](https://discuss.elastic.co/u/poornima)\
**Post date:** [February 16, 2016, 1:10pm UTC](https://discuss.elastic.co/t/how-to-use-elk-to-extract-data-from-specific-dates-from-date-field-in-csv/41623/11 "2016-02-16T13:10:06Z")

</div>

In console, am able to get the correct timestamp field but not in kibana.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 16, 2016, 1:22pm UTC](https://discuss.elastic.co/t/how-to-use-elk-to-extract-data-from-specific-dates-from-date-field-in-csv/41623/12 "2016-02-16T13:22:03Z")

</div>

Yes, but again I think that's because you're not looking at the right data in Kibana. What's printed to the console is that same data that's sent to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![poornima](https://avatars.discourse-cdn.com/v4/letter/p/85f322/32.png) [@poornima](https://discuss.elastic.co/u/poornima)\
**Post date:** [February 17, 2016, 2:42am UTC](https://discuss.elastic.co/t/how-to-use-elk-to-extract-data-from-specific-dates-from-date-field-in-csv/41623/13 "2016-02-17T02:42:08Z")

</div>

I modified time picker and could see the data in kibana. Thanks for the pointers Magnus 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:02pm UTC](https://discuss.elastic.co/t/how-to-use-elk-to-extract-data-from-specific-dates-from-date-field-in-csv/41623/14 "2017-07-06T14:02:05Z")

</div>


