# Kibana all time \_dateparsefailure

**URL:** https://discuss.elastic.co/t/kibana-all-time-dateparsefailure/142404
**Category:** Logstash
**Created:** [July 31, 2018, 3:25pm UTC](https://discuss.elastic.co/t/kibana-all-time-dateparsefailure/142404 "2018-07-31T15:25:37Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![satana](https://avatars.discourse-cdn.com/v4/letter/s/f04885/32.png) [@satana](https://discuss.elastic.co/u/satana)
#### Post date: [July 31, 2018, 3:25pm UTC](https://discuss.elastic.co/t/kibana-all-time-dateparsefailure/142404/1 "2018-07-31T15:25:37Z")

</div>

Hello. I Have \_dateparsefailure in Kibana, but in logstash, I think, it's ok  
Can you help my ?

echo "[gmail.video.google.com](http://gmail.video.google.com);10.111.13.232;31/Jul/2018:17:11:59 +0300;200;0.006;13820;GET /online/js/final.css?v=22e0aff8dsfdsfdsfdsf57e789146d01373aa2705b048e3d6e3f HTTP/1.1;0.006;127.0.0.1:8010;200;-;CmpF+ltgbip5i3sSA5siAg==;Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Safari/537.36" | /usr/share/logstash/bin/logstash -e 'input { stdin {} } filter {grok {match =\>{"message" =\> "%{DATA:VHOSTtmp};%{IP:remote\_addr};%{HTTPDATE:timestamp};%{NUMBER:status};%{DATA:request\_time\_ms};%{NUMBER:bytes\_sent};%{DATA:request\_method} %{DATA:request\_uri} %{DATA:protocol\_version};%{DATA:upstream\_response\_time\_ms};%{DATA:upstream\_addr};%{DATA:upstream\_status};%{DATA:http\_x\_forwarded\_for};%{DATA:cookie\_CID};%{GREEDYDATA:http\_user\_agent}"}} date {match =\> ["timestamp","dd/MMM/yyyy:HH:mm:ss +0300"]}}'  
WARNING: Could not find logstash.yml which is typically located in $LS\_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults  
Could not find log4j2 configuration at path /usr/share/logstash/config/log4j2.properties. Using default config which logs errors to the console  
[INFO] 2018-07-31 18:17:43.817 [main] scaffold - Initializing module {:module\_name=\>"netflow", :directory=\>"/usr/share/logstash/modules/netflow/configuration"}  
[INFO] 2018-07-31 18:17:43.835 [main] scaffold - Initializing module {:module\_name=\>"fb\_apache", :directory=\>"/usr/share/logstash/modules/fb\_apache/configuration"}  
[WARN] 2018-07-31 18:17:44.868 [LogStash::Runner] multilocal - Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[INFO] 2018-07-31 18:17:45.256 [LogStash::Runner] runner - Starting Logstash {"logstash.version"=\>"6.2.2"}  
[INFO] 2018-07-31 18:17:45.562 [Api Webserver] agent - Successfully started Logstash API endpoint {:port=\>9600}  
[INFO] 2018-07-31 18:17:47.042 [Ruby-0-Thread-1: /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:22] pipeline - Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>2, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50}  
[INFO] 2018-07-31 18:17:47.341 [Ruby-0-Thread-1: /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:22] pipeline - Pipeline started succesfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x3c2c29cd@/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:246 run\>"}  
[INFO] 2018-07-31 18:17:47.388 [Ruby-0-Thread-1: /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:22] agent - Pipelines running {:count=\>1, :pipelines=\>["main"]}  
{  
"@timestamp" =\> 2018-07-31T14:11:59.000Z,  
"http\_user\_agent" =\> "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Safari/537.36",  
"upstream\_addr" =\> "127.0.0.1:8010",  
"request\_method" =\> "GET",  
"http\_x\_forwarded\_for" =\> "-",  
"upstream\_response\_time\_ms" =\> "0.006",  
"@version" =\> "1",  
"message" =\> "[gmail.video.google.com](http://gmail.video.google.com);10.111.13.232;31/Jul/2018:17:11:59 +0300;200;0.006;13820;GET /online/js/final.css?v=22e0aff8dsfdsfdsfdsf57e789146d01373aa2705b048e3d6e3f HTTP/1.1;0.006;127.0.0.1:8010;200;-;CmpF+ltgbip5i3sSA5siAg==;Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Safari/537.36",  
"remote\_addr" =\> "10.111.13.232",  
"status" =\> "200",  
"request\_uri" =\> "/online/js/final.css?v=22e0aff8dsfdsfdsfdsf57e789146d01373aa2705b048e3d6e3f",  
"upstream\_status" =\> "200",  
"cookie\_CID" =\> "CmpF+ltgbip5i3sSA5siAg==",  
"timestamp" =\> "31/Jul/2018:17:11:59 +0300",  
"host" =\> "NSTB-Logstash",  
"request\_time\_ms" =\> "0.006",  
"bytes\_sent" =\> "13820",  
"protocol\_version" =\> "HTTP/1.1",  
"VHOSTtmp" =\> "[gmail.video.google.com](http://gmail.video.google.com)"  
}  
[INFO] 2018-07-31 18:17:47.873 [[main]-pipeline-manager] pipeline - Pipeline has terminated {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x3c2c29cd@/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:246 run\>"}

---

<div class="post-metadata">

### Author: ![Charaf\_Ahmed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/charaf_ahmed/32/30467_2.png) [@Charaf\_Ahmed](https://discuss.elastic.co/u/Charaf_Ahmed)
#### Post date: [July 31, 2018, 3:29pm UTC](https://discuss.elastic.co/t/kibana-all-time-dateparsefailure/142404/2 "2018-07-31T15:29:02Z")

</div>

"\_dateparsefailure" is a problem with date conversion in the logstash configuration file.

---

<div class="post-metadata">

### Author: ![satana](https://avatars.discourse-cdn.com/v4/letter/s/f04885/32.png) [@satana](https://discuss.elastic.co/u/satana)
#### Post date: [July 31, 2018, 3:32pm UTC](https://discuss.elastic.co/t/kibana-all-time-dateparsefailure/142404/3 "2018-07-31T15:32:54Z")

</div>

problem in data filter, I suppose, but -

input  
31/Jul/2018:17:11:59 +0300  
date {match =\> ["timestamp","dd/MMM/yyyy:HH:mm:ss +0300"]}}  
output  
"timestamp" =\> "31/Jul/2018:17:11:59 +0300",  
"@timestamp" =\> 2018-07-31T14:11:59.000Z,

Here it's ok

---

<div class="post-metadata">

### Author: ![satana](https://avatars.discourse-cdn.com/v4/letter/s/f04885/32.png) [@satana](https://discuss.elastic.co/u/satana)
#### Post date: [July 31, 2018, 3:41pm UTC](https://discuss.elastic.co/t/kibana-all-time-dateparsefailure/142404/4 "2018-07-31T15:41:28Z")

</div>

With Z options same story  
Logstash - ok, Kibana - error

echo "31/Jul/2018:17:11:59 +0300" | /usr/share/logstash/bin/logstash -e 'input { stdin {} } filter {date {match =\> ["message","dd/MMM/yyyy:HH:mm:ss Z"]}}'

{  
"message" =\> "31/Jul/2018:17:11:59 +0300",  
"host" =\> "NSTB-Logstash",  
"@timestamp" =\> 2018-07-31T14:11:59.000Z,  
"@version" =\> "1"  
}

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [July 31, 2018, 4:31pm UTC](https://discuss.elastic.co/t/kibana-all-time-dateparsefailure/142404/5 "2018-07-31T16:31:16Z")

</div>

> [@satana](#):
>
> echo "31/Jul/2018:17:11:59 +0300" | /usr/share/logstash/bin/logstash -e 'input { stdin {} } filter {date {match =\> ["message","dd/MMM/yyyy:HH:mm:ss Z"]}}'

That is working just fine. 17:11 +0300 is 14:11 UTC.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 28, 2018, 4:31pm UTC](https://discuss.elastic.co/t/kibana-all-time-dateparsefailure/142404/6 "2018-08-28T16:31:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
