# Logstash date field error

**URL:** <https://discuss.elastic.co/t/logstash-date-field-error/236463>\
**Category:** Elasticsearch\
**Created:** [June 10, 2020, 8:42am UTC](https://discuss.elastic.co/t/logstash-date-field-error/236463 "2020-06-10T08:42:07Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![bdn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bdn/32/136737_2.png) [@bdn](https://discuss.elastic.co/u/bdn)\
**Post date:** [June 10, 2020, 8:42am UTC](https://discuss.elastic.co/t/logstash-date-field-error/236463/1 "2020-06-10T08:42:07Z")

</div>

I have log files from where I've to query documents through the date field. Here is the log date format.  
**2020-06-10 14:01:26**  
I've defined a grok pattern like below in Logstash for the log.

```auto
filter {
    grok {
           match => {"message" => "%{YEAR:YEAR}-%{MONTHNUM:MONTHNUM}-%{MONTHDAY:MONTHDAY} %{TIME:time} ........."
          }}
    mutate {
            add_field => {
              "log_timestamp" => "%{YEAR}-%{MONTHNUM}-%{MONTHDAY}"
 }}

```

Date field **log\_timestamp** is working as expected but I've been receiving Logstash error message frequently because of this grok pattern. In a day, if there's a log document of around 100 then 10 logs will be discarded because of this error. Is there any better way to parse the log file and get the **date field**?

**Error msg:**

_[2020-06-10T06:43:18,756][WARN][logstash.outputs.elasticsearch][log] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"log-2020-06", :\_type=\>"\_doc", :routing=\>nil}, #LogStash::Event:0x7f4158ff], :response=\>{"index"=\>{"\_index"=\>"log-2020-06", "\_type"=\>"\_doc", "\_id"=\>"KSSvm3IBbBjRTTrvQZx8", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field [log\_timestamp] of type [date] in document with id 'KSSvm3IBbBjRTTrvQZx8'. Preview of field's value: '%{YEAR}-%{MONTHNUM}-%{MONTHDAY}'", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"failed to parse date field [%{YEAR}-%{MONTHNUM}-%{MONTHDAY}] with format [strict\_date\_optional\_time||epoch\_millis]", "caused\_by"=\>{"type"=\>"date\_time\_parse\_exception", "reason"=\>"date\_time\_parse\_exception: Failed to parse with all enclosed parsers"}}}}}}_

---

<div class="post-metadata">

**Author:** ![bdn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bdn/32/136737_2.png) [@bdn](https://discuss.elastic.co/u/bdn)\
**Post date:** [June 15, 2020, 6:39am UTC](https://discuss.elastic.co/t/logstash-date-field-error/236463/2 "2020-06-15T06:39:08Z")

</div>

Can anyone suggest on this?

---

<div class="post-metadata">

**Author:** ![gab.bernasconi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gab.bernasconi/32/57955_2.png) [@gab.bernasconi](https://discuss.elastic.co/u/gab.bernasconi)\
**Post date:** [June 15, 2020, 1:26pm UTC](https://discuss.elastic.co/t/logstash-date-field-error/236463/3 "2020-06-15T13:26:52Z")

</div>

I don't see anything wrong with your parsing. Nonetheless, if you are getting errors, I would try using explicit regular expressions, to make sure that you are getting what you expect.

For example, if your pattern is always **exactly** as you quoted, you could use this to parse it:

```auto
filter {
  grok {
    match => { "message" => "(?<YEAR>\d{4})-(?<MONTHNUM>\d{2})-(?<MONTHDAY>\d{2})\s(?<HOUR>\d{2}):(?<MINUTE>\d{2}):(?<SECOND>\d{2})" }
  }
}

```

These matches are _stricter_ than the grok patterns you quoted, but maybe this can help to narrow down the problem.

---

<div class="post-metadata">

**Author:** ![bdn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bdn/32/136737_2.png) [@bdn](https://discuss.elastic.co/u/bdn)\
**Post date:** [June 18, 2020, 10:13am UTC](https://discuss.elastic.co/t/logstash-date-field-error/236463/4 "2020-06-18T10:13:02Z")

</div>

Thank you for your reply.

I've followed your advice but still having the same issue. Here is the error message,

* * *

`"reason"=>"failed to parse date field [%{YEAR}-%{MONTHNUM}-%{MONTHDAY}] with format [strict_date_optional_time||epoch_millis]", "caused_by"=>{"type"=>"date_time_parse_exception", "reason"=>"date_time_parse_exception: Failed to parse with all enclosed parsers"}}}}}}`

* * *

---

<div class="post-metadata">

**Author:** ![gab.bernasconi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gab.bernasconi/32/57955_2.png) [@gab.bernasconi](https://discuss.elastic.co/u/gab.bernasconi)\
**Post date:** [June 18, 2020, 12:40pm UTC](https://discuss.elastic.co/t/logstash-date-field-error/236463/5 "2020-06-18T12:40:28Z")

</div>

What's the content of the `message` field for the message that gives you the error?

---

<div class="post-metadata">

**Author:** ![bdn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bdn/32/136737_2.png) [@bdn](https://discuss.elastic.co/u/bdn)\
**Post date:** [June 18, 2020, 3:34pm UTC](https://discuss.elastic.co/t/logstash-date-field-error/236463/6 "2020-06-18T15:34:49Z")

</div>

Error is related to `log_timestamp` field, date field.  
I found a similar problem reported on Github too.

> <https://github.com/elastic/logstash/issues/10994>
>
> While trying to index some tweets, I noted that certain date values do not parse using the "date" filter if a...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 16, 2020, 3:35pm UTC](https://discuss.elastic.co/t/logstash-date-field-error/236463/7 "2020-07-16T15:35:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
