# Is there any existing grok{} pattern for date format YYYY-MM-DD?

**URL:** <https://discuss.elastic.co/t/is-there-any-existing-grok-pattern-for-date-format-yyyy-mm-dd/284269>\
**Category:** Kibana\
**Created:** [September 15, 2021, 11:00am UTC](https://discuss.elastic.co/t/is-there-any-existing-grok-pattern-for-date-format-yyyy-mm-dd/284269 "2021-09-15T11:00:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![shi](https://avatars.discourse-cdn.com/v4/letter/s/f14d63/32.png) [@shi](https://discuss.elastic.co/u/shi)\
**Post date:** [September 15, 2021, 11:00am UTC](https://discuss.elastic.co/t/is-there-any-existing-grok-pattern-for-date-format-yyyy-mm-dd/284269/1 "2021-09-15T11:00:52Z")

</div>

# [Is there any existing grok{} pattern for date format YYYY-MM-DD?

I get error when i use %{DATE:datefield}, tried %{CUSTOM\_DATE:datefield} also  
,  
that also resulted in failure

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [September 15, 2021, 6:23pm UTC](https://discuss.elastic.co/t/is-there-any-existing-grok-pattern-for-date-format-yyyy-mm-dd/284269/2 "2021-09-15T18:23:37Z")

</div>

Hi @shi,

Welcome, the user guide may help here: [Debug grok expressions | Kibana Guide [7.14] | Elastic](https://www.elastic.co/guide/en/kibana/current/xpack-grokdebugger.html). What is your sample data? Thanks.

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [September 15, 2021, 7:08pm UTC](https://discuss.elastic.co/t/is-there-any-existing-grok-pattern-for-date-format-yyyy-mm-dd/284269/3 "2021-09-15T19:08:22Z")

</div>

Try `(?<field_name>%{YEAR}-%{MONTHNUM}-%{MONTHDAY})`.

---

<div class="post-metadata">

**Author:** ![shi](https://avatars.discourse-cdn.com/v4/letter/s/f14d63/32.png) [@shi](https://discuss.elastic.co/u/shi)\
**Post date:** [September 16, 2021, 5:14am UTC](https://discuss.elastic.co/t/is-there-any-existing-grok-pattern-for-date-format-yyyy-mm-dd/284269/4 "2021-09-16T05:14:28Z")

</div>

Sir,

It is working now . thanks a lot ..

The sample log data was

2021-09-14T05:24:41.957467+05:30 10.101.200.1 date=2021-09-14 devname="W02" devid="3916803686" logid="0419016384" type="utm"  
2021-09-14T05:31:41.358729+05:30 10.101.200.1 date=2021-09-14 devname="W02" devid="3916803686" logid="0419016384" type="utm"  
2021-09-14T08:20:58.352756+05:30 10.101.200.1 date=2021-09-14 devname="W02" devid="3916803686" logid="0419016384" type="utm"

File beat is directly sening logs to elasticsearch. For this i am trying to create inex pattern using Kibana upload sample file

I tried  
%{TIMESTAMP\_ISO8601:timestamp} %{IP:ipaddress} date=(?%{YEAR}[/-]%{MONTHNUM}[/-]%{MONTHDAY}) devname=%{QUOTEDSTRING:devname} devid=%{QUOTEDSTRING:devid} logid=%{QUOTEDSTRING:logid} type=%{QUOTEDSTRING:type}

it is working and even combining the year month and date components together and considering newdate as date format

befor that i was trying date=%{YEAR}[/-]%{MONTHNUM}[/-]%{MONTHDAY} and i was wondering how to combine them . thanks for the pattern

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2021, 5:14am UTC](https://discuss.elastic.co/t/is-there-any-existing-grok-pattern-for-date-format-yyyy-mm-dd/284269/5 "2021-10-14T05:14:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
