# Logstash couldn't index date field for few log lines

**URL:** <https://discuss.elastic.co/t/logstash-couldnt-index-date-field-for-few-log-lines/185726>\
**Category:** Logstash\
**Created:** [June 13, 2019, 8:44pm UTC](https://discuss.elastic.co/t/logstash-couldnt-index-date-field-for-few-log-lines/185726 "2019-06-13T20:44:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![chandukreddi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chandukreddi/32/29241_2.png) [@chandukreddi](https://discuss.elastic.co/u/chandukreddi)\
**Post date:** [June 13, 2019, 8:44pm UTC](https://discuss.elastic.co/t/logstash-couldnt-index-date-field-for-few-log-lines/185726/1 "2019-06-13T20:44:38Z")

</div>

Hello Experts,

I am getting below error while logstashing log file, but I do see only few of them are failing with this error and remaining logstashed with out any issues, why failing only few even there is no change in the date format?

**Logstash error**

`> [2019-06-13T13:35:32,159][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"cas-log-1", :_type=>"doc", :routing=>nil}, #<LogStash::Event:0x49eb0676>], :response=>{"index"=>{"_index"=>"cas-log-1", "_type"=>"doc", "_id"=>"Y-uNUmsBOZFRwoF5eqNl", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [logdate] of type [date] in document with id 'Y-uNUmsBOZFRwoF5eqNl'", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"Invalid format: \"2019-06-12 05:48:57\" is malformed at \" 05:48:57\""}}}}}`

Here is my date filter

```
date {
match => ["logdate", "yyyy-MM-dd HH:mm:ss"]
target => "logdate"
timezone => "PST8PDT"
}

```

Here is my log line looks like

`INFO [Service Thread] 2019-06-11 07:57:44,325 StatusLogger.java:56 - ReadStage 2 0 10091338228 0 0`

Thanks  
Chandra

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 13, 2019, 10:07pm UTC](https://discuss.elastic.co/t/logstash-couldnt-index-date-field-for-few-log-lines/185726/2 "2019-06-13T22:07:25Z")

</div>

It apparentlly does not expect your date field to contain a time. Check the [mapping](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-mapping.html) of the index and see [what formats](https://www.elastic.co/guide/en/elasticsearch/reference/current/date.html#multiple-date-formats) it allows.

---

<div class="post-metadata">

**Author:** ![chandukreddi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chandukreddi/32/29241_2.png) [@chandukreddi](https://discuss.elastic.co/u/chandukreddi)\
**Post date:** [June 13, 2019, 11:06pm UTC](https://discuss.elastic.co/t/logstash-couldnt-index-date-field-for-few-log-lines/185726/3 "2019-06-13T23:06:36Z")

</div>

Hi @Badger,

But how come other log lines being parsed?  
**Parsed data from ES:**  
{  
"\_index": "cas-log-1",  
"\_type": "doc",  
"\_id": "bfqnUmsBOZFRwoF5gQbL",  
"\_version": 1,  
"\_score": null,  
"\_source": {  
"tags": [  
"cassandra",  
"\_grokparsefailure",  
"cass\_rest\_all"  
],  
"java\_file": "LocalAntiCompactionTask",  
"threadId": 76983,  
"path": "/opt/caslogs/mStore\_PROD\_MSG\_Cluster-diagnostics-2019\_06\_13\_05\_59\_01\_UTC/nodes/10.175.51.39/logs/cassandra/system.log",  
"process": "AntiCompactionExecutor",  
`"logdate": "2019-06-13T05:59:23.000Z",`  
"line\_number": 140,  
"message": "[repair #5ee0def0-8da0-11e9-a189-c50b5d88e2be] Starting anticompaction for OpsCenter.backup\_reports on 0/0 sstables on 517 ranges.",  
"@timestamp": "2019-06-13T21:03:56.952Z",  
"@version": "1",  
"host": "0.0.0.0",  
"level": "INFO"  
},  
"fields": {  
"@timestamp": [  
"2019-06-13T21:03:56.952Z"  
],  
**"logdate": [**  
\*\* "2019-06-13T05:59:23.000Z"\*\*  
]  
},  
"sort": [  
1560405563000  
]  
}

Thanks  
Chandra

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 14, 2019, 12:04am UTC](https://discuss.elastic.co/t/logstash-couldnt-index-date-field-for-few-log-lines/185726/4 "2019-06-14T00:04:06Z")

</div>

> [@chandukreddi](#):
>
> But how come other log lines being parsed?

I do not know. Your elasticsearch instance contains the information that should allow you to determine that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 12, 2019, 12:04am UTC](https://discuss.elastic.co/t/logstash-couldnt-index-date-field-for-few-log-lines/185726/5 "2019-07-12T00:04:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
