# Logstah date help

**URL:** <https://discuss.elastic.co/t/logstah-date-help/69171>\
**Category:** Logstash\
**Created:** [December 15, 2016, 1:58pm UTC](https://discuss.elastic.co/t/logstah-date-help/69171 "2016-12-15T13:58:11Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![pierre](https://avatars.discourse-cdn.com/v4/letter/p/d07c76/32.png) [@pierre](https://discuss.elastic.co/u/pierre)\
**Post date:** [December 15, 2016, 1:58pm UTC](https://discuss.elastic.co/t/logstah-date-help/69171/1 "2016-12-15T13:58:11Z")

</div>

i have this :  
01-11-2015;17:41:01;641

filter {  
grok {  
break\_on\_match =\> "false"  
match =\> { "message" =\> '%{DATA}%{DATE\_EU:Date};%{TIME:Date};%{NUMBER:Nombre}%{DATA}'}  
}  
}  
Here my date = string and i want date = date so i use

date {  
match =\> ["Date", "dd MM YYYY HH:mm:ss"]  
}

but i have  
{  
"\_index": "logstash-2016.12.15",  
"\_type": "Vmware",  
"id": "AVkCgGy96Itcz\_3yhMg",  
"\_score": null,  
"\_source": {  
"Nombre": 751,  
"path": "/var/log/StatVM/test10.log",  
"@timestamp": "2016-12-15T12:41:27.524Z",  
"@version": "1",  
"host": "localhost.localdomain",  
"message": "14-12-2016;11:20:01;751",  
"type": "Vmware",  
"Date": [  
"14-12-2016",  
"11:20:01"  
],  
"tags": [  
"\_dateparsefailure",  
"\_grokparsefailure"  
]  
},  
"fields": {  
"@timestamp": [  
1481805687524  
]  
},  
"sort": [  
1481805687524  
]  
}  
},  
"fields": {  
"@timestamp": [  
1481804404819  
]  
},  
"sort": [  
1481804404819  
]  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 15, 2016, 2:05pm UTC](https://discuss.elastic.co/t/logstah-date-help/69171/2 "2016-12-15T14:05:41Z")

</div>

Your `Date` field doesn't contain a "dd MM YYYY HH:mm:ss" string, it's an two-element array. Suggestion:

```nohighlight
grok {
  break_on_match => "false"
  match => {
    "message" => '%{DATA}%{DATE_EU:Date};%{TIME:Time};%{NUMBER:Nombre}%{DATA}'
  }
  add_field => {
    "timestamp" => "%{Date} %{Time}"
  }
}

date {
  match => ["timestamp", "dd MM YYYY HH:mm:ss"]
}

```

---

<div class="post-metadata">

**Author:** ![pierre](https://avatars.discourse-cdn.com/v4/letter/p/d07c76/32.png) [@pierre](https://discuss.elastic.co/u/pierre)\
**Post date:** [December 19, 2016, 6:00pm UTC](https://discuss.elastic.co/t/logstah-date-help/69171/4 "2016-12-19T18:00:21Z")

</div>

i have grokfail 😕

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 19, 2016, 9:15pm UTC](https://discuss.elastic.co/t/logstah-date-help/69171/5 "2016-12-19T21:15:11Z")

</div>

Please show your configuration and a sample event, preferably from a `stdout { codec => rubydebug }` output.

---

<div class="post-metadata">

**Author:** ![pierre](https://avatars.discourse-cdn.com/v4/letter/p/d07c76/32.png) [@pierre](https://discuss.elastic.co/u/pierre)\
**Post date:** [December 20, 2016, 2:22pm UTC](https://discuss.elastic.co/t/logstah-date-help/69171/7 "2016-12-20T14:22:41Z")

</div>

my log : 22-11-2016 23:32:01;703

my filter :

filter {  
grok {  
break\_on\_match =\> "false"  
match =\> {  
"message" =\> '%{DATA}%{DATE\_EU:Date} %{TIME:Time};%{NUMBER:Nombre:float}%{DATA}'  
}  
add\_field =\> {  
"timestamp" =\> "%{Date} %{Time}"  
}  
}

date {  
match =\> ["timestamp", "dd-MM-YYYY HH:mm:ss"]  
}  
}  
you can see :

"@timestamp": "2016-11-22T22:32:01.000Z",  
"tags": [],  
"timestamp": "22-11-2016 23:32:01"  
},

in my index patterns i have : @timestamp , type = date so i can chose this Time-field

me seconde timestamp add by add\_field but in my index patterns i have timestamp.keyword , type = sting so i can't use this timestamp , i can't chose this timestamp in my Time-field

i want compare the number with the time

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 20, 2016, 2:28pm UTC](https://discuss.elastic.co/t/logstah-date-help/69171/8 "2016-12-20T14:28:35Z")

</div>

This looks correct. Keep in mind that `@timestamp` is UTC.

---

<div class="post-metadata">

**Author:** ![pierre](https://avatars.discourse-cdn.com/v4/letter/p/d07c76/32.png) [@pierre](https://discuss.elastic.co/u/pierre)\
**Post date:** [December 20, 2016, 2:52pm UTC](https://discuss.elastic.co/t/logstah-date-help/69171/9 "2016-12-20T14:52:40Z")

</div>

> [@magnusbaeck](#):
>
> This looks correct. Keep in mind that @timestamp is UTC

:o sorry i go sleep LOL

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 17, 2017, 2:52pm UTC](https://discuss.elastic.co/t/logstah-date-help/69171/10 "2017-01-17T14:52:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
