# Importing palo alto logs, " failed to parse " error on time

**URL:** <https://discuss.elastic.co/t/importing-palo-alto-logs-failed-to-parse-error-on-time/41660>\
**Category:** Elasticsearch\
**Created:** [February 12, 2016, 9:26pm UTC](https://discuss.elastic.co/t/importing-palo-alto-logs-failed-to-parse-error-on-time/41660 "2016-02-12T21:26:53Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alex\_Mendez](https://avatars.discourse-cdn.com/v4/letter/a/9de0a6/32.png) [@Alex\_Mendez](https://discuss.elastic.co/u/Alex_Mendez)\
**Post date:** [February 12, 2016, 9:26pm UTC](https://discuss.elastic.co/t/importing-palo-alto-logs-failed-to-parse-error-on-time/41660/1 "2016-02-12T21:26:53Z")

</div>

I'm trying to import palo alto logs, and there are two fields ReceiveTime and GenerateTime, with time stamp as below

```
       "ReceiveTime" => "2016/02/12 19:03:09",
      "GenerateTime" => "2016/02/12 19:03:09",

```

in the logstash.conf , I have a date plugin as follows, which appears to match fine  
date {  
#timezone =\> "America/New\_York"  
timezone =\> "America/Chicago"  
#match =\> ["GenerateTime", "YYYY/MM/dd HH:mm"]

Problem is ReceiveTime should only be HH:mm , but it appends date also

```
       "ReceiveTime" => "2016/02/12 19:03:09",

```

The error seems to be when it attempts to push it to ES.

status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse [ReceiveTime]", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception",  
"reason"=\>"Invalid format: "2016/02/12 19:03:03" is malformed at "/02/12 19:03:03""}}}}, :level=\>:warn}

How do I resolve this? I am new to ES/LS

thank you

---

<div class="post-metadata">

**Author:** ![Alex\_Mendez](https://avatars.discourse-cdn.com/v4/letter/a/9de0a6/32.png) [@Alex\_Mendez](https://discuss.elastic.co/u/Alex_Mendez)\
**Post date:** [February 12, 2016, 9:27pm UTC](https://discuss.elastic.co/t/importing-palo-alto-logs-failed-to-parse-error-on-time/41660/2 "2016-02-12T21:27:57Z")

</div>

the GenertateTime is no commented out...

match =\> ["GenerateTime", "YYYY/MM/dd HH:mm"]

---

<div class="post-metadata">

**Author:** ![hrishikeshtak](https://avatars.discourse-cdn.com/v4/letter/h/858c86/32.png) [@hrishikeshtak](https://discuss.elastic.co/u/hrishikeshtak)\
**Post date:** [August 2, 2016, 11:21am UTC](https://discuss.elastic.co/t/importing-palo-alto-logs-failed-to-parse-error-on-time/41660/3 "2016-08-02T11:21:36Z")

</div>

Hi,

I am facing same issue.  
Grok Filters is parsing logs properly but elasticsearch is giving exception

Logs of elasticsearch :

MapperParsingException[failed to parse [GenerateTime]]; nested: IllegalArgumentException[Invalid format: "2016/08/02 00:35:44" is malformed at "/08/02 00:35:44"];

Please help 🙂

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 2, 2016, 11:33am UTC](https://discuss.elastic.co/t/importing-palo-alto-logs-failed-to-parse-error-on-time/41660/4 "2016-08-02T11:33:42Z")

</div>

Your mapping in elasticsearch for this field is incorrect.

---

<div class="post-metadata">

**Author:** ![hrishikeshtak](https://avatars.discourse-cdn.com/v4/letter/h/858c86/32.png) [@hrishikeshtak](https://discuss.elastic.co/u/hrishikeshtak)\
**Post date:** [August 2, 2016, 11:41am UTC](https://discuss.elastic.co/t/importing-palo-alto-logs-failed-to-parse-error-on-time/41660/5 "2016-08-02T11:41:10Z")

</div>

so every time, if any new fields occurs, we have to update elasticsearch mappings?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 2, 2016, 11:57am UTC](https://discuss.elastic.co/t/importing-palo-alto-logs-failed-to-parse-error-on-time/41660/6 "2016-08-02T11:57:42Z")

</div>

Yes. Unless you want this field to be a String.

If you want it to be a Date, so you are able to run date histograms for example on it), then you need to provide the right mapping.

Here you did not tell us what is your mapping/config/... So hard to tell more.

---

<div class="post-metadata">

**Author:** ![hrishikeshtak](https://avatars.discourse-cdn.com/v4/letter/h/858c86/32.png) [@hrishikeshtak](https://discuss.elastic.co/u/hrishikeshtak)\
**Post date:** [August 2, 2016, 4:11pm UTC](https://discuss.elastic.co/t/importing-palo-alto-logs-failed-to-parse-error-on-time/41660/7 "2016-08-02T16:11:15Z")

</div>

Thanks David, I got it.  
I updated logstash output filter to add elasticsearch mapping :

# 30-elasticsearch-output.conf

output {  
if [type] == "paloalto\_firewall" {  
elasticsearch { hosts =\> ["localhost:9200"]  
template =\> "/etc/logstash/elasticsearch-template.json"  
template\_overwrite =\> true  
}  
}  
}

# elasticsearch-template.json

{  
"template" : "logstash-_",  
"settings" : {  
"index.refresh\_interval" : "5s"  
},  
"mappings" : {  
"\_default\_" : {  
"\_all" : {"enabled" : true},  
"dynamic\_templates" : [ {  
"message\_field" : {  
"match" : "message",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "string", "index" : "analyzed", "omit\_norms" : true  
}  
}  
}, {  
"string\_fields" : {  
"match" : "_",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "string", "index" : "analyzed", "omit\_norms" : true,  
"fields" : {  
"raw" : {"type": "string", "index" : "not\_analyzed", "ignore\_above" : 256}  
}  
}  
}  
} ],  
"properties" : {  
"@version": { "type": "string", "index": "not\_analyzed" },  
"geoip" : {  
"type" : "object",  
"dynamic": true,  
"path": "full",  
"properties" : {  
"location" : { "type" : "geo\_point", "lat\_lon" : true, "geohash" : true }  
}  
},  
"SourceGeo" : {  
"type" : "object",  
"dynamic": true,  
"path": "full",  
"properties" : {  
"location" : {"type" : "geo\_point", "lat\_lon" : true, "geohash" : true }  
}  
},  
"DestinationGeo": {  
"type": "object",  
"dynamic": true,  
"path": "full",  
"properties" : {  
"location" : { "type" : "geo\_point", "lat\_lon" : true, "geohash" : true }  
}  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:30pm UTC](https://discuss.elastic.co/t/importing-palo-alto-logs-failed-to-parse-error-on-time/41660/8 "2017-07-05T22:30:40Z")

</div>


