# Logstash date field problem

**URL:** <https://discuss.elastic.co/t/logstash-date-field-problem/223388>\
**Category:** Logstash\
**Created:** [March 12, 2020, 5:49pm UTC](https://discuss.elastic.co/t/logstash-date-field-problem/223388 "2020-03-12T17:49:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![tomba2k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomba2k/32/64351_2.png) [@tomba2k](https://discuss.elastic.co/u/tomba2k)\
**Post date:** [March 12, 2020, 5:49pm UTC](https://discuss.elastic.co/t/logstash-date-field-problem/223388/1 "2020-03-12T17:49:23Z")

</div>

I cannot get logstash to format custom field to be suitable for sort in kibana.  
pipeline filter config is:

> filter {  
> if ([fields][log\_type] == "zira\_prod\_log") {  
> grok {  
> match =\> { "message" =\> "[%{TIMESTAMP\_ISO8601:timestamp}] %{NOTSPACE:log\_type}: %{NOTSPACE:field3} [%{NOTSPACE:verb}] %{NOTSPACE:api\_uri} %{GREEDYDATA:jsonstring1} %{GREEDYDATA:jsonstring2}" }  
> patterns\_dir =\> ["/etc/logstash/.patterns"]  
> }  
> mutate {  
> rename =\> { "source" =\> "file" }  
> replace =\> { "[type]" =\> "%{[fields][environment]}-zira\_prod\_log" }  
> }  
> date {  
> timezone =\> "Europe/Zagreb"  
> match =\> ["timestamp", "YYYY-MM-dd HH:mm:ss.SSS", "ISO8601"]  
> target =\> "@timestamp"  
> }  
> }  
> }  
> neither **@timestamp** is overwritten with **timestamp** nor is timestamp sortable (because it gets type text and not date)  
> input is beats, output elastic, i tried multiple variations, always delete es index, restart logstash on pipeline changes, and recreate index pattern, but no combo i've tried helped

how es shows field:

> ```
> "type" : {
> "type" : "text",
> "fields" : {
> "keyword" : {
> "type" : "keyword",
> "ignore_above" : 256
> }
> }
> }
> 
> ```

log example:

> [2020-03-11 14:38:18.123456] zira\_api.INFO: REQUEST [GET] [https://x.y.z/examplepath/category?filter](https://x.y.z/examplepath/category?filter)... {"payload":"[object] (Infrastructure\External\...: )"} {"tags":{"request\_id":"d8886a16-..."}}

---

<div class="post-metadata">

**Author:** ![tomba2k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomba2k/32/64351_2.png) [@tomba2k](https://discuss.elastic.co/u/tomba2k)\
**Post date:** [March 13, 2020, 4:53pm UTC](https://discuss.elastic.co/t/logstash-date-field-problem/223388/2 "2020-03-13T16:53:14Z")

</div>

found the problem, changed:

> match =\> ["timestamp", "YYYY-MM-dd HH:mm:ss.SSS", "ISO8601"]

to:

> match =\> ["timestamp", "YYYY-MM-dd HH:mm:ss.SSS", "YYYY-MM-dd HH:mm:ss.SSSSSS", "ISO8601"]

now the data gets into @timestamp, all ok

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 10, 2020, 4:53pm UTC](https://discuss.elastic.co/t/logstash-date-field-problem/223388/3 "2020-04-10T16:53:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
