# Logstash date filter error

**URL:** <https://discuss.elastic.co/t/logstash-date-filter-error/313253>\
**Category:** Logstash\
**Created:** [August 30, 2022, 12:35pm UTC](https://discuss.elastic.co/t/logstash-date-filter-error/313253 "2022-08-30T12:35:29Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [August 30, 2022, 12:35pm UTC](https://discuss.elastic.co/t/logstash-date-filter-error/313253/1 "2022-08-30T12:35:29Z")

</div>

I have this field in my logs `event_time=2022-08-30 17:30:42.000`

my logstash pipeline file is

```auto
filter {
if "average_weight" in [tags] {
kv {
source=>"message"
target => "test"
field_split=>","
}

mutate {
rename => {
"[test][name]" =>"name"
"[test][weight]" => "weight"
"[test][event_time]" => "[event][time]"
}

date {
match =>["[event][time]","YYYY-MM-dd HH:mm:ss.SSS"]
}

remove_tag => ["beats_input_codec_plain_applied"]
convert => {
"weight" => "float"
}

}
}
}

```

I am getting the error at date filter everthing is fine according to me but i am getting error

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 30, 2022, 12:39pm UTC](https://discuss.elastic.co/t/logstash-date-filter-error/313253/2 "2022-08-30T12:39:45Z")

</div>

What is the error? You didn't share any error log or how is your real output.

Please share the error and the output you are getting, also share a sample of your message so it is possible to try to replicate.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [August 31, 2022, 1:41am UTC](https://discuss.elastic.co/t/logstash-date-filter-error/313253/3 "2022-08-31T01:41:01Z")

</div>

> [@Aniket\_Pant](#):
>
> ```auto
> date {
> match =>["[event][time]","YYYY-MM-dd HH:mm:ss.SSS"]
> }
> 
> ```

Try with low letter yyyy

`match =>["[event][time]","yyyy-MM-dd HH:mm:ss.SSS"]`

`Y year of era (>=0) year 1996`  
`y year year 1996`

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [August 31, 2022, 8:33am UTC](https://discuss.elastic.co/t/logstash-date-filter-error/313253/4 "2022-08-31T08:33:10Z")

</div>

Getting the error

```auto
[2022-08-31T14:00:28,549][ERROR][logstash.agent] Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"Expected one of [\\t\\r\\n], \"#\", \"=>\" at line 25, column 6 (byte 406) after filter {\nif \"average_weight\" in [tags] { \nkv {\nsource=>\"message\"\ntarget => \"test\"\nfield_split=>\",\"\n}\n\nmutate {\nrename => {\n\"[test][name]\" =>\"name\"\n\"[test][weight]\" => \"weight\"\n\"[test][event_time]\" => \"[event][time]\"\n}\n\ndate ", :backtrace=>["/home/aniket/logstash/logstash-core/lib/logstash/compiler.rb:32:in `compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:189:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:72:in `initialize'", "/home/aniket/logstash/logstash-core/lib/logstash/java_pipeline.rb:48:in `initialize'", "/home/aniket/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:52:in `execute'", "/home/aniket/logstash/logstash-core/lib/logstash/agent.rb:388:in `block in converge_state'"]}
[2022-08-31T14:00:29,797][INFO][org.reflections.Reflections] Reflections took 307 ms to scan 1 urls, producing 119 keys and 419 values

```

I've used your date time format

```auto
filter {
if "average_weight" in [tags] {
kv {
source=>"message"
target => "test"
field_split=>","
}

mutate {
rename => {
"[test][name]" =>"name"
"[test][weight]" => "weight"
"[test][event_time]" => "[event][time]"
}

date {
match =>["[event][time]","yyyy-MM-dd HH:mm:ss.SSS"]
}

remove_tag => ["beats_input_codec_plain_applied"]
convert => {
"weight" => "float"
}

}
}
}

```

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [August 31, 2022, 8:41am UTC](https://discuss.elastic.co/t/logstash-date-filter-error/313253/5 "2022-08-31T08:41:08Z")

</div>

Hi @leandrojmp  
I am using beat input where filebeat is sending data to logstash and i want to parse this event\_time field as a timestamp  
_test.log_

```auto
name=David Kluesner,weight=36,event_time=2022-08-31 14:01:02.066109
name=Pamela Ware,weight=47,event_time=2022-08-31 14:02:01.322111
name=Paul Folsom,weight=40,event_time=2022-08-31 14:02:01.327286
name=Dennis Cochran,weight=34,event_time=2022-08-31 14:02:01.328276
name=Lois Macy,weight=31,event_time=2022-08-31 14:02:01.341071
name=Roberto Kelly,weight=36,event_time=2022-08-31 14:03:01.597030
name=Wesley Ingram,weight=33,event_time=2022-08-31 14:03:01.598002
name=Daniel Kitchen,weight=40,event_time=2022-08-31 14:03:01.601372
name=Julie Obrien,weight=46,event_time=2022-08-31 14:03:01.602028
name=David Taylor,weight=24,event_time=2022-08-31 14:03:01.602174
name=Charles Randle,weight=23,event_time=2022-08-31 14:03:01.604975

```

I was getting this below error

```auto
[2022-08-30T18:05:53,173][ERROR][logstash.agent] Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"Expected one of [\\t\\r\\n], \"#\", \"=>\" at line 25, column 6 (byte 406) after filter {\nif \"average_weight\" in [tags] { \nkv {\nsource=>\"message\"\ntarget => \"test\"\nfield_split=>\",\"\n}\n\nmutate {\nrename => {\n\"[test][name]\" =>\"name\"\n\"[test][weight]\" => \"weight\"\n\"[test][event_time]\" => \"[event][time]\"\n}\n\ndate ", :backtrace=>["/home/aniket/logstash/logstash-core/lib/logstash/compiler.rb:32:in `compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:189:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:72:in `initialize'", "/home/aniket/logstash/logstash-core/lib/logstash/java_pipeline.rb:48:in `initialize'", "/home/aniket/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:52:in `execute'", "/home/aniket/logstash/logstash-core/lib/logstash/agent.rb:388:in `block in converge_state'"]}

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [August 31, 2022, 8:59am UTC](https://discuss.elastic.co/t/logstash-date-filter-error/313253/6 "2022-08-31T08:59:56Z")

</div>

> [@Aniket\_Pant](#):
>
> ```auto
> mutate {
> rename => {
> "[test][name]" =>"name"
> "[test][weight]" => "weight"
> "[test][event_time]" => "[event][time]"
> }
> 
> ```

Add one more **}**

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [August 31, 2022, 9:27am UTC](https://discuss.elastic.co/t/logstash-date-filter-error/313253/7 "2022-08-31T09:27:18Z")

</div>

I have used only mutate filter and under this i am using `rename,convert,date,remove_tag`.

```auto
mutate {
rename => {
"[test][name]" =>"name"
"[test][weight]" => "weight"
"[test][event_time]" => "[event][time]"
}

date {
match =>["[event][time]","yyyy-MM-dd HH:mm:ss.SSS"]
}

remove_tag => ["beats_input_codec_plain_applied"]
convert => {
"weight" => "float"
}

}

```

every curly braces are completed

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [August 31, 2022, 9:49am UTC](https://discuss.elastic.co/t/logstash-date-filter-error/313253/8 "2022-08-31T09:49:44Z")

</div>

Date is not part of mutate, however, if is working, leave it 😊

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [August 31, 2022, 9:56am UTC](https://discuss.elastic.co/t/logstash-date-filter-error/313253/9 "2022-08-31T09:56:40Z")

</div>

Oops i didn't see this in logstash documentation 😅

```auto
mutate {
rename => {
"[test][name]" =>"name"
"[test][weight]" => "weight"
"[test][event_time]" => "[event][time]"
}

remove_tag => ["beats_input_codec_plain_applied"]
convert => {
"weight" => "float"
}

}

date {
match =>["[event][time]","YYYY-MM-dd HH:mm:ss.SSS"]
}

```

Its working now

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 31, 2022, 11:55am UTC](https://discuss.elastic.co/t/logstash-date-filter-error/313253/10 "2022-08-31T11:55:47Z")

</div>

Just one tip, if you are going to use more than one mutate action in the same field, as destination our source, and need them to happen in a specific order, you should use different mutate blocks.

This is an important not in the documentation:

> Each mutation must be in its own code block if the sequence of operations needs to be preserved.

In your case you are doing multiple mutates in the `weight` field, in your case it worked because `rename` is processed before `convert`, but depending on the action the order will change.

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [August 31, 2022, 12:07pm UTC](https://discuss.elastic.co/t/logstash-date-filter-error/313253/11 "2022-08-31T12:07:58Z")

</div>

Thank you @leandrojmp i will update my code 😊

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 28, 2022, 12:08pm UTC](https://discuss.elastic.co/t/logstash-date-filter-error/313253/12 "2022-09-28T12:08:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
