# Ingest node: Invalid format...date and time is malformed

**URL:** <https://discuss.elastic.co/t/ingest-node-invalid-format-date-and-time-is-malformed/97156>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 15, 2017, 10:37pm UTC](https://discuss.elastic.co/t/ingest-node-invalid-format-date-and-time-is-malformed/97156 "2017-08-15T22:37:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![hungl99](https://avatars.discourse-cdn.com/v4/letter/h/ed8c4c/32.png) [@hungl99](https://discuss.elastic.co/u/hungl99)\
**Post date:** [August 15, 2017, 10:37pm UTC](https://discuss.elastic.co/t/ingest-node-invalid-format-date-and-time-is-malformed/97156/1 "2017-08-15T22:37:44Z")

</div>

I try to parse a csv file using a pipeline but got into problem with the date format. Appreciate any help!

Here is my pipiline:

```auto
{
  "pipeline": {
  "description" : "parse stat logs",
  "processors": [
      {
      "grok": {
        "field": "message",
        "patterns": ["%{DATESTAMP:log.datetime}\",\"%{HOSTNAME:log.machineName}\",\"%{HOSTNAME:log.domainDS}\",\"%{DATA:log.requestID}\",\"%{URIPATH:log.pageUrl}\",\"%{NUMBER:log.totalDuration}\",\"%{NUMBER:log.actionDuration}\",\"%{NUMBER:log.viewDuration}\",\"%{NUMBER:log.prefetchData-1-Duration}\",\"%{NUMBER:log.prefetchData-2-Duration}\",\"%{NUMBER:log.routingDuration}\",\"%{NUMBER:log.unknownDuration}\""],
        "on_failure": [
        	{
        		"set":{
        			"field": "ingestError",
        			"value": "{{ _ingest.on_failure_message }}"
        		}
        	},
           	{
    						"date": {
    						"field":"log.datetime",
    						"target_field":"log.datetime",
    						"formats": ["dd/MMM/yyyy HH:mm:ss.SSS"]
    						}
        	},
        		{
        		"set":{
        			"field": "log.datetime",
        			"value": "{{ @timestamp }}"
        		}
        	}
 
        ]
      }
    }
  ]
},
"docs":[
  {
    "_source": {"message":"\"7/31/2017 15:37:56.362\",\"EKL-DSDEV\",\"localhost\",\"+hn7XkuM+06ACvXijjo5Ww\",\"/modelos\",\"3417\",\"8\",\"538\",\"2026\",\"92\",\"2851\",\"-12\""}
  }
  ]
}

```

2017-08-15T18:16:52-04:00 DBG PublishEvents: 5 events have been published to elasticsearch in 9.9982ms.  
2017-08-15T18:16:52-04:00 DBG Bulk item insert failed (i=0, status=500): {"type":"exception","reason":"java.lang.IllegalArgumentException: java.lang.IllegalArgumentException: unable to parse date [2017-08-15T22:14:15.635Z]","caused\_by":{"type":"illegal\_argument\_exception","reason":"java.lang.IllegalArgumentException: unable to parse date [2017-08-15T22:14:15.635Z]","caused\_by":{"type":"illegal\_argument\_exception","reason":"unable to parse date [2017-08-15T22:14:15.635Z]","caused\_by":{"type":"illegal\_argument\_exception","reason":"Invalid format: "2017-08-15T22:14:15.635Z" is malformed at "17-08-15T22:14:15.635Z""}}},"header":{"processor\_type":"date"}}  
2017-08-15T18:16:52-04:00 DBG Bulk item insert failed (i=1, status=500): {"type":"exception","reason":"java.lang.IllegalArgumentException: java.lang.IllegalArgumentException: unable to parse date [2017-08-15T22:14:15.635Z]","caused\_by":{"type":"illegal\_argument\_exception","reason":"java.lang.IllegalArgumentException: unable to parse date [2017-08-15T22:14:15.635Z]","caused\_by":{"type":"illegal\_argument\_exception","reason":"unable to parse date [2017-08-15T22:14:15.635Z]","caused\_by":{"type":"illegal\_argument\_exception","reason":"Invalid format: "2017-08-15T22:14:15.635Z" is malformed at "17-08-15T22:14:15.635Z""}}},"header":{"processor\_type":"date"}}  
2017-08-15T18:16:52-04:00 DBG Bulk item insert failed (i=2, status=500): {"type":"exception","reason":"java.lang.IllegalArgumentException: java.lang.IllegalArgumentException: unable to parse date [2017-08-15T22:14:15.635Z]","caused\_by":{"type":"illegal\_argument\_exception","reason":"java.lang.IllegalArgumentException: unable to parse date [2017-08-15T22:14:15.635Z]","caused\_by":{"type":"illegal\_argument\_exception","reason":"unable to parse date [2017-08-15T22:14:15.635Z]","caused\_by":{"type":"illegal\_argument\_exception","reason":"Invalid format: "2017-08-15T22:14:15.635Z" is malformed at "17-08-15T22:14:15.635Z""}}},"header":{"processor\_type":"date"}}  
2017-08-15T18:16:52-04:00 DBG Bulk item insert failed (i=3, status=500): {"type":"exception","reason":"java.lang.IllegalArgumentException: java.lang.IllegalArgumentException: unable to parse date [2017-08-15T22:14:15.635Z]","caused\_by":{"type":"illegal\_argument\_exception","reason":"java.lang.IllegalArgumentException: unable to parse date [2017-08-15T22:14:15.635Z]","caused\_by":{"type":"illegal\_argument\_exception","reason":"unable to parse date [2017-08-15T22:14:15.635Z]","caused\_by":{"type":"illegal\_argument\_exception","reason":"Invalid format: "2017-08-15T22:14:15.635Z" is malformed at "17-08-15T22:14:15.635Z""}}},"header":{"processor\_type":"date"}}  
2017-08-15T18:16:52-04:00 DBG Bulk item insert failed (i=4, status=500): {"type":"exception","reason":"java.lang.IllegalArgumentException: java.lang.IllegalArgumentException: unable to parse date [2017-08-15T22:14:15.635Z]","caused\_by":{"type":"illegal\_argument\_exception","reason":"java.lang.IllegalArgumentException: unable to parse date [2017-08-15T22:14:15.635Z]","caused\_by":{"type":"illegal\_argument\_exception","reason":"unable to parse date [2017-08-15T22:14:15.635Z]","caused\_by":{"type":"illegal\_argument\_exception","reason":"Invalid format: "2017-08-15T22:14:15.635Z" is malformed at "17-08-15T22:14:15.635Z""}}},"header":{"processor\_type":"date"}}  
2017-08-15T18:16:52-04:00 DBG Registry file updated. 6 states written.  
2017-08-15T18:16:52-04:00 INFO Total non-zero values: filebeat.harvester.closed=6 filebeat.harvester.started=6 libbeat.es.call\_count.PublishEvents=47635 libbeat.es.publish.read\_bytes=21396008 libbeat.es.publish.write\_bytes=117496007 libbeat.es.published\_and\_acked\_events=493 libbeat.es.published\_but\_not\_acked\_events=141840 libbeat.publisher.published\_events=2037 registrar.states.current=6 registrar.writes=1  
2017-08-15T18:16:52-04:00 INFO Uptime: 2m36.7110224s

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 15, 2017, 11:05pm UTC](https://discuss.elastic.co/t/ingest-node-invalid-format-date-and-time-is-malformed/97156/2 "2017-08-15T23:05:36Z")

</div>

The date format looks to be incorrect. Try using `mm/DD/yyyy HH:mm:ss.SSS`.

Also the pipeline looks to be setup incorrectly because you have the `date` and `set` processors defined as part of the `on_failure` handler. I'm guessing you mean for those to come after the `grok` processor as part of the main pipeline.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 12, 2017, 11:05pm UTC](https://discuss.elastic.co/t/ingest-node-invalid-format-date-and-time-is-malformed/97156/3 "2017-09-12T23:05:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
