# Ingesting both 'standard' timestamp syslog and ISO8601 timestamped syslog

**URL:** https://discuss.elastic.co/t/ingesting-both-standard-timestamp-syslog-and-iso8601-timestamped-syslog/132128
**Category:** Logstash
**Created:** [May 16, 2018, 1:07pm UTC](https://discuss.elastic.co/t/ingesting-both-standard-timestamp-syslog-and-iso8601-timestamped-syslog/132128 "2018-05-16T13:07:19Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![nathharp](https://avatars.discourse-cdn.com/v4/letter/n/f1d935/32.png) [@nathharp](https://discuss.elastic.co/u/nathharp)
#### Post date: [May 16, 2018, 1:07pm UTC](https://discuss.elastic.co/t/ingesting-both-standard-timestamp-syslog-and-iso8601-timestamped-syslog/132128/1 "2018-05-16T13:07:19Z")

</div>

As per [https://www.elastic.co/guide/en/logstash/current/logstash-config-for-filebeat-modules.html](https://www.elastic.co/guide/en/logstash/current/logstash-config-for-filebeat-modules.html) we are happily ingesting Filebeat \> logstash \> elasticsearch for system logs that use the 'standard' syslog timestamp (eg May 16 13:58:17). However we have some systems that output in ISO8601 format (2018-05-16T14:06:23.106124+01:00).

Any suggestions on how I can modify the reference config to be able to filter both?

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [May 16, 2018, 1:35pm UTC](https://discuss.elastic.co/t/ingesting-both-standard-timestamp-syslog-and-iso8601-timestamped-syslog/132128/2 "2018-05-16T13:35:26Z")

</div>

> [@nathharp](#):
>
> Any suggestions on how I can modify the reference config to be able to filter both?

The date filter [match](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html#plugins-filters-date-match) option takes an array, which can include multiple date formats to try.

---

<div class="post-metadata">

### Author: ![nathharp](https://avatars.discourse-cdn.com/v4/letter/n/f1d935/32.png) [@nathharp](https://discuss.elastic.co/u/nathharp)
#### Post date: [May 16, 2018, 2:14pm UTC](https://discuss.elastic.co/t/ingesting-both-standard-timestamp-syslog-and-iso8601-timestamped-syslog/132128/3 "2018-05-16T14:14:26Z")

</div>

ok, so I could replace:

match =\> { "message" =\> ["%{SYSLOGTIMESTAMP:[system][syslog][timestamp]} %{SYSLOGHOST:[system][syslog][hostname]} %{DATA:[system][syslog][program]}(?:[%{POSINT:[system][syslog][pid]}])?: %{GREEDYMULTILINE:[system][syslog][message]}"] }

with match =\> { "message" =\> ["%{SYSLOGTIMESTAMP:[system][syslog][timestamp]} %{SYSLOGHOST:[system][syslog][hostname]} %{DATA:[system][syslog][program]}(?:[%{POSINT:[system][syslog][pid]}])?: %{GREEDYMULTILINE:[system][syslog][message]}, %{TIMESTAMP\_ISO8601:[system][syslog][timestamp]} %{SYSLOGHOST:[system][syslog][hostname]} %{DATA:[system][syslog][program]}(?:[%{POSINT:[system][syslog][pid]}])?: %{GREEDYMULTILINE:[system][syslog][message]}"] }

and that should do the trick?

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [May 16, 2018, 2:27pm UTC](https://discuss.elastic.co/t/ingesting-both-standard-timestamp-syslog-and-iso8601-timestamped-syslog/132128/4 "2018-05-16T14:27:39Z")

</div>

Oh, yes, grok takes an array as well, so you can match both patterns against the line, as well as matching both date formats against [system][syslog][timestamp] in the date filter.

---

<div class="post-metadata">

### Author: ![nathharp](https://avatars.discourse-cdn.com/v4/letter/n/f1d935/32.png) [@nathharp](https://discuss.elastic.co/u/nathharp)
#### Post date: [May 16, 2018, 3:01pm UTC](https://discuss.elastic.co/t/ingesting-both-standard-timestamp-syslog-and-iso8601-timestamped-syslog/132128/5 "2018-05-16T15:01:24Z")

</div>

ok, great, I'll investigate further! Thanks for the help.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 13, 2018, 3:01pm UTC](https://discuss.elastic.co/t/ingesting-both-standard-timestamp-syslog-and-iso8601-timestamped-syslog/132128/6 "2018-06-13T15:01:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
