# Logsatsh String To Date convertion

**URL:** <https://discuss.elastic.co/t/logsatsh-string-to-date-convertion/205705>\
**Category:** Logstash\
**Created:** [October 29, 2019, 3:15pm UTC](https://discuss.elastic.co/t/logsatsh-string-to-date-convertion/205705 "2019-10-29T15:15:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![haythem](https://avatars.discourse-cdn.com/v4/letter/h/45deac/32.png) [@haythem](https://discuss.elastic.co/u/haythem)\
**Post date:** [October 29, 2019, 3:15pm UTC](https://discuss.elastic.co/t/logsatsh-string-to-date-convertion/205705/1 "2019-10-29T15:15:07Z")

</div>

Hello Guys , so lately i've trying to insert some data from txt file into elasticsearch index , but i'm having a problem converting string field to date type , here is my logsatsh conf :

```
input {
 
file {
path => "C:/Elastic/Rapport_finale.txt"
start_position => "beginning"
}

}
 filter {
    
      csv {
	  separator => ";"
		 columns =>["ID","DATE_SITUATION","HEURE","COMPANY","NOM_COMPANY","DATE_SIT","NBRE_OPERATION_TOTAL","OPERATION_CAISSE","LR_LATITUDE","LR_LONGITUDE","SOMME","LIB_REGION","LIB_ZONE","LIB_AGENCE","DATE_UNIQ"]
		 
      } 
	  	  date {
        match => ["DATE_SIT", "yyyy-MM-dd HH:mm:ss"]
	
      }
	  
	
	  mutate {
   add_field => { "[location][lat]" => "%{LR_LONGITUDE}" }
   add_field => { "[location][lon]" => "%{LR_LATITUDE}" }
  }
   mutate {
    convert => {"[location][lat]" => "float"}
    convert => {"[location][lon]" => "float"}
   }
}
 

output{

  elasticsearch {
  hosts => "*.*.*.*:9200"
  index => "rapport_index_dg_finale_test"
  #document_type => "my_type"
  #action => "update"
  #doc_as_upsert => true
  #document_id => "%{id}"
  user => "logstash_admin"
  password => " ********"
 }
 stdout{ codec => rubydebug}

 }

```

and this is the output in elasticsearch  
 ![54](https://us1.discourse-cdn.com/elastic/original/3X/3/d/3dddafa56b8d2dd1abb66ab955ba46be1c96689e.jpeg)

any idea what am i doing wrong !!

elasticsearch version 7.4  
logstash version 7.4

thanks.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 29, 2019, 3:35pm UTC](https://discuss.elastic.co/t/logsatsh-string-to-date-convertion/205705/2 "2019-10-29T15:35:00Z")

</div>

In the rubydebug output does DATE\_SIT look like this?

```
2019-10-29T15:23:49.056Z

```

If it does then logstash has correctly parsed it and elasticsearch is converting it back to text because the field has already been mapped as text. Rolling over to a new index might help in that case.

---

<div class="post-metadata">

**Author:** ![haythem](https://avatars.discourse-cdn.com/v4/letter/h/45deac/32.png) [@haythem](https://discuss.elastic.co/u/haythem)\
**Post date:** [October 31, 2019, 4:48pm UTC](https://discuss.elastic.co/t/logsatsh-string-to-date-convertion/205705/3 "2019-10-31T16:48:07Z")

</div>

@Badger i managed to fix my problem by adding this  
date {  
match =\> ["DATE\_SIT", "ISO8601", "YYYY-MM-dd HH:mm:ss", "YYYY-MM-dd HH:mm:ss.ZZZ"]  
target =\> "DATE"  
locale =\> "en"  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 28, 2019, 5:03pm UTC](https://discuss.elastic.co/t/logsatsh-string-to-date-convertion/205705/4 "2019-11-28T17:03:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
