# Ingest node processor "date": unable to parse date

**URL:** <https://discuss.elastic.co/t/ingest-node-processor-date-unable-to-parse-date/73975>\
**Category:** Elasticsearch\
**Created:** [February 5, 2017, 9:47am UTC](https://discuss.elastic.co/t/ingest-node-processor-date-unable-to-parse-date/73975 "2017-02-05T09:47:28Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![John16](https://avatars.discourse-cdn.com/v4/letter/j/ea666f/32.png) [@John16](https://discuss.elastic.co/u/John16)\
**Post date:** [February 5, 2017, 9:47am UTC](https://discuss.elastic.co/t/ingest-node-processor-date-unable-to-parse-date/73975/1 "2017-02-05T09:47:28Z")

</div>

Hello,

I am using the following pattern to parse date in Logstash:  
date {  
match =\> ["date", "yyyy-MM-dd'T'HH:mm:ss"]  
}

(note 'T' in the middle). It works as expected.

Now I want to move away from LS and use Ingest node instead.

I define the following processor:

"date": {  
"field": "date",  
"target\_field": "timestamp",  
"formats": ["yyyy-MM-dd'T'HH:mm:ss"]  
}

and ES throws an exception:

"type" : "exception",  
"reason" : "java.lang.IllegalArgumentException: Illegal pattern component: T",  
"caused\_by" : {  
"type" : "illegal\_argument\_exception",  
"reason" : "Illegal pattern component: T"  
},  
"header" : {  
"processor\_type" : "date"  
}  
},  
"status" : 500

What's wrong with it? How can I define a date pattern to match a date with "T" in the middle?

Thanks.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 5, 2017, 10:56am UTC](https://discuss.elastic.co/t/ingest-node-processor-date-unable-to-parse-date/73975/2 "2017-02-05T10:56:06Z")

</div>

Look at the formats here: [https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-date-format.html#mapping-date-format](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-date-format.html#mapping-date-format)

`basic_date_time` is what you want I think.

---

<div class="post-metadata">

**Author:** ![John16](https://avatars.discourse-cdn.com/v4/letter/j/ea666f/32.png) [@John16](https://discuss.elastic.co/u/John16)\
**Post date:** [February 5, 2017, 11:11am UTC](https://discuss.elastic.co/t/ingest-node-processor-date-unable-to-parse-date/73975/3 "2017-02-05T11:11:36Z")

</div>

Yes, but why does it throw exception if I define date format inline (with the same syntax)? And also it works as expected with Logstash.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 5, 2017, 11:29am UTC](https://discuss.elastic.co/t/ingest-node-processor-date-unable-to-parse-date/73975/4 "2017-02-05T11:29:38Z")

</div>

Did you try with the one I proposed ?

I mean that in docs, it's mentioned that it must be a JODA date format.

Might be a bug though.

---

<div class="post-metadata">

**Author:** ![John16](https://avatars.discourse-cdn.com/v4/letter/j/ea666f/32.png) [@John16](https://discuss.elastic.co/u/John16)\
**Post date:** [February 5, 2017, 12:10pm UTC](https://discuss.elastic.co/t/ingest-node-processor-date-unable-to-parse-date/73975/5 "2017-02-05T12:10:44Z")

</div>

If I use  
"date": {  
"field": "date",  
"target\_field": "date",  
"formats": ["basic\_date\_time\_no\_millis"]  
},

I get

"type" : "exception",  
"reason" : "java.lang.IllegalArgumentException: Illegal pattern component: b",  
"caused\_by" : {  
"type" : "illegal\_argument\_exception",  
"reason" : "Illegal pattern component: b"  
},  
"header" : {  
"processor\_type" : "date"  
}  
},  
"status" : 500

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 5, 2017, 12:28pm UTC](https://discuss.elastic.co/t/ingest-node-processor-date-unable-to-parse-date/73975/6 "2017-02-05T12:28:34Z")

</div>

Interesting.

I'm AFK so I can't really check.

May be open an issue then and link to this thread?

---

<div class="post-metadata">

**Author:** ![John16](https://avatars.discourse-cdn.com/v4/letter/j/ea666f/32.png) [@John16](https://discuss.elastic.co/u/John16)\
**Post date:** [February 6, 2017, 9:44am UTC](https://discuss.elastic.co/t/ingest-node-processor-date-unable-to-parse-date/73975/7 "2017-02-06T09:44:05Z")

</div>

> <https://github.com/elastic/elasticsearch/issues/22982>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2017, 9:45am UTC](https://discuss.elastic.co/t/ingest-node-processor-date-unable-to-parse-date/73975/8 "2017-03-06T09:45:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
