# Log files are not current

**URL:** <https://discuss.elastic.co/t/log-files-are-not-current/45391>\
**Category:** Logstash\
**Created:** [March 24, 2016, 7:23pm UTC](https://discuss.elastic.co/t/log-files-are-not-current/45391 "2016-03-24T19:23:30Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![rvaedex23](https://avatars.discourse-cdn.com/v4/letter/r/9f8e36/32.png) [@rvaedex23](https://discuss.elastic.co/u/rvaedex23)\
**Post date:** [March 24, 2016, 7:23pm UTC](https://discuss.elastic.co/t/log-files-are-not-current/45391/1 "2016-03-24T19:23:30Z")

</div>

I am running the Kibana GUI and the log files are not current: This the output of the first log:

March 24th 2016, 15:17:08.747  
message:2015-08-13 02:36:24,038 DEBUG [AptService] [org.springframework.scheduling.quartz.SchedulerFactoryBean#0\_Worker-1] Request APT :: Request ID : 157471, Priority

The time stamp is : March 24th 2016, 15:17:08.747  
the message date is 8/13/2015. How come the log file doesn't generate the most current logs?  
How can I correct this.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 24, 2016, 7:25pm UTC](https://discuss.elastic.co/t/log-files-are-not-current/45391/2 "2016-03-24T19:25:48Z")

</div>

It seems like you don't have a date filter to parse the date in the input logs.

---

<div class="post-metadata">

**Author:** ![rvaedex23](https://avatars.discourse-cdn.com/v4/letter/r/9f8e36/32.png) [@rvaedex23](https://discuss.elastic.co/u/rvaedex23)\
**Post date:** [March 24, 2016, 7:33pm UTC](https://discuss.elastic.co/t/log-files-are-not-current/45391/3 "2016-03-24T19:33:12Z")

</div>

How can I do that?

---

<div class="post-metadata">

**Author:** ![michalterbert](https://avatars.discourse-cdn.com/v4/letter/m/848f3c/32.png) [@michalterbert](https://discuss.elastic.co/u/michalterbert)\
**Post date:** [March 24, 2016, 11:22pm UTC](https://discuss.elastic.co/t/log-files-are-not-current/45391/4 "2016-03-24T23:22:39Z")

</div>

You should use a date filter, in your example:  
Timestamp is: March 24th 2016, 15:17:08.747  
i used this: [joda.timeFormat](http://joda-time.sourceforge.net/apidocs/org/joda/time/format/DateTimeFormat.html)  
Snippet below should works 😉

```
filter{
date { match => ["MMMM dddd YYYY, HH:mm:ss.SSS"] }
}
```

---

<div class="post-metadata">

**Author:** ![rvaedex23](https://avatars.discourse-cdn.com/v4/letter/r/9f8e36/32.png) [@rvaedex23](https://discuss.elastic.co/u/rvaedex23)\
**Post date:** [March 25, 2016, 12:41am UTC](https://discuss.elastic.co/t/log-files-are-not-current/45391/5 "2016-03-25T00:41:48Z")

</div>

Sorry I am new to ELK.

I have 4 files /etc/logstash/conf.d  
rw-r--r--. 1 root root 194 Mar 10 13:32 02-beats-input.conf  
-rw-r--r--. 1 root root 155 Mar 22 10:15 10-syslog.conf  
-rw-r--r--. 1 root root 470 Mar 24 20:24 10-syslog-filter.conf  
-rw-r--r--. 1 root root 220 Mar 23 14:26 30-elasticsearch-output.conf

Do I put the code in here, this the contents of file 10-syslog-filter.conf, where would I put it exactly.

filter {

if [type] == "syslog" {

```
grok {

  match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }

  add_field => ["received_at", "%{@timestamp}"]

  add_field => ["received_from", "%{host}"]

}

syslog_pri { }

date {

  match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]

}

```

}

}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 25, 2016, 10:04am UTC](https://discuss.elastic.co/t/log-files-are-not-current/45391/6 "2016-03-25T10:04:39Z")

</div>

> [@michalterbert](#):
>
> ```
> date { match => ["MMMM dddd YYYY, HH:mm:ss.SSS"] }
> 
> ```

The field name is missing. Should be something like:

```
date { match => ["name-of-field-with-timestamp", "MMMM dddd YYYY, HH:mm:ss.SSS"] }

```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 25, 2016, 10:07am UTC](https://discuss.elastic.co/t/log-files-are-not-current/45391/7 "2016-03-25T10:07:32Z")

</div>

> [@rvaedex23](#):
>
> Do I put the code in here, this the contents of file 10-syslog-filter.conf, where would I put it exactly.

That date filter is for syslog messages but the message with the incorrect timestamp doesn't look like a syslog message. It probably came via the beats input, and those message are apparently not processed by a working date filter.

---

<div class="post-metadata">

**Author:** ![rvaedex23](https://avatars.discourse-cdn.com/v4/letter/r/9f8e36/32.png) [@rvaedex23](https://discuss.elastic.co/u/rvaedex23)\
**Post date:** [March 25, 2016, 12:45pm UTC](https://discuss.elastic.co/t/log-files-are-not-current/45391/8 "2016-03-25T12:45:06Z")

</div>

so where would I put the date field?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 25, 2016, 1:33pm UTC](https://discuss.elastic.co/t/log-files-are-not-current/45391/9 "2016-03-25T13:33:08Z")

</div>

Put it in whatever configuration file you have for parsing the events that arrive via the beats input. If you're not parsing those events you should start doing that. Since you have a separate file for taking care of syslog events I suggest you create a similar one for dealing with events arriving via the beats input.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:05am UTC](https://discuss.elastic.co/t/log-files-are-not-current/45391/10 "2017-07-06T05:05:21Z")

</div>


