# Issue with date format

**URL:** <https://discuss.elastic.co/t/issue-with-date-format/209598>\
**Category:** Logstash\
**Created:** [November 27, 2019, 2:19am UTC](https://discuss.elastic.co/t/issue-with-date-format/209598 "2019-11-27T02:19:27Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ShaneLillie\_RAD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shanelillie_rad/32/57131_2.png) [@ShaneLillie\_RAD](https://discuss.elastic.co/u/ShaneLillie_RAD)\
**Post date:** [November 27, 2019, 2:19am UTC](https://discuss.elastic.co/t/issue-with-date-format/209598/1 "2019-11-27T02:19:27Z")

</div>

We're using this date filter:

```
filter {                                                                                              
  date {                                                                                                
    match => ["ts", "yyyy-MM-dd'T'HH:mm:ss'Z'.SSS", "yyyy-MM-dd'T'HH:mm:ss.SSSSSSSSS'Z'", "ISO8601"]
    timezone => "UTC"                                                                                 
  }                                                                                                   
}                                                                                                     

```

And that seems to work for our ISO8601 dates, but we're seeing this spamming our logstash logs:

> [2019-11-26T18:18:20,636][WARN][logstash.outputs.elasticsearch][main] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"filebeat-6.3.0-2019.11.27", :\_type=\>"\_doc", :routing=\>nil}, #LogStash::Event:0x44858188], :response=\>{"index"=\>{"\_index"=\>"filebeat-6.3.0-2019.11.27", "\_type"=\>"\_doc", "\_id"=\>"S-2mqm4B6hZBfKts\_AtW", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field [ts] of type [date] in document with id 'S-2mqm4B6hZBfKts\_AtW'. Preview of field's value: '2019-11-27T02:18:15Z.599'", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"failed to parse date field [2019-11-27T02:18:15Z.599] with format [strict\_date\_optional\_time||epoch\_millis]", "caused\_by"=\>{"type"=\>"date\_time\_parse\_exception", "reason"=\>"Failed to parse with all enclosed parsers"}}}}}}

It seems like we should be correctly matching those dates, so I'm not sure what exactly we're doing wrong. The filter used to not have ISO8601 in it and we've just added it today, but I'm not sure how adding that would have caused this. Any ideas what we might be doing wrong?

---

<div class="post-metadata">

**Author:** ![chandu5565](https://avatars.discourse-cdn.com/v4/letter/c/c57346/32.png) [@chandu5565](https://discuss.elastic.co/u/chandu5565)\
**Post date:** [November 27, 2019, 4:43am UTC](https://discuss.elastic.co/t/issue-with-date-format/209598/2 "2019-11-27T04:43:27Z")

</div>

What is the format of "ts" field that you are using and how does it look like.

---

<div class="post-metadata">

**Author:** ![chandu5565](https://avatars.discourse-cdn.com/v4/letter/c/c57346/32.png) [@chandu5565](https://discuss.elastic.co/u/chandu5565)\
**Post date:** [November 27, 2019, 5:13am UTC](https://discuss.elastic.co/t/issue-with-date-format/209598/3 "2019-11-27T05:13:40Z")

</div>

As per my understanding the "ts" field type is updated as Date in your index mapping. But when the "ts" value is not in the ISO8061 it is unable to parse the field. so check the timestamp value that generated for "ts". In the error that you posted it shows that "ts" received input as 2019-11-27T02:18:15Z.599 which cannot be parsed by logstash.

---

<div class="post-metadata">

**Author:** ![ShaneLillie\_RAD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shanelillie_rad/32/57131_2.png) [@ShaneLillie\_RAD](https://discuss.elastic.co/u/ShaneLillie_RAD)\
**Post date:** [November 27, 2019, 4:37pm UTC](https://discuss.elastic.co/t/issue-with-date-format/209598/4 "2019-11-27T16:37:09Z")

</div>

Yeah, I think you're right. I think the ts values we've been using in some applications has been parsing as a string and now that we're putting an ISO8601 value in there it's parsing as a date and they're conflicting. Bleh. I guess one of them is going to move to a different field then.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 27, 2019, 4:52pm UTC](https://discuss.elastic.co/t/issue-with-date-format/209598/5 "2019-11-27T16:52:01Z")

</div>

The date filter parses [ts] and updates @timestamp. It does not modify [ts]. elasticsearch expects [ts] to be a date, either because you have a template that says so, or because on the first document that had a [ts] field it was a LogStash::Timestamp.

However, none of the default date parsers in elasticsearch can parse 2019-11-27T02:18:15Z.599, so you need to add a custom parser in your index template.

---

<div class="post-metadata">

**Author:** ![ShaneLillie\_RAD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shanelillie_rad/32/57131_2.png) [@ShaneLillie\_RAD](https://discuss.elastic.co/u/ShaneLillie_RAD)\
**Post date:** [November 27, 2019, 5:09pm UTC](https://discuss.elastic.co/t/issue-with-date-format/209598/6 "2019-11-27T17:09:19Z")

</div>

Ahhh, ok, the custom parser seems like it might be the right way to go. Does this seem like the correct way to do that?

```
PUT /_template/date_mapping
{
  "index_patterns": ["*"],
  "mappings": {
    "properties": {
      "ts": {
        "type": "date",
        "format": "yyyy-MM-dd'T'HH:mm:ss'Z'.SSS||strict_date_optional_time||epoch_millis"
      }
    }
  }
}

```

That must not be the full extent of what I need to do because after doing so, and verifying that the mapping shows up in the list when I GET /\_template, I'm still getting the same error.

---

<div class="post-metadata">

**Author:** ![ShaneLillie\_RAD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shanelillie_rad/32/57131_2.png) [@ShaneLillie\_RAD](https://discuss.elastic.co/u/ShaneLillie_RAD)\
**Post date:** [November 27, 2019, 6:19pm UTC](https://discuss.elastic.co/t/issue-with-date-format/209598/7 "2019-11-27T18:19:29Z")

</div>

Tried reindexing and that didn't work. We've already lost the data since the date mismatch discards the entry so I'll try deleting the index and letting elastic re-create it.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 27, 2019, 6:46pm UTC](https://discuss.elastic.co/t/issue-with-date-format/209598/8 "2019-11-27T18:46:12Z")

</div>

> [@ShaneLillie\_RAD](#):
>
> Does this seem like the correct way to do that?

It looks right to me, although I do not have elasticsearch running so I am unable to test it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 25, 2019, 6:46pm UTC](https://discuss.elastic.co/t/issue-with-date-format/209598/9 "2019-12-25T18:46:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
