# Logstash date filter, kibana index template warning in logs

**URL:** <https://discuss.elastic.co/t/logstash-date-filter-kibana-index-template-warning-in-logs/272094>\
**Category:** Logstash\
**Created:** [May 4, 2021, 5:06pm UTC](https://discuss.elastic.co/t/logstash-date-filter-kibana-index-template-warning-in-logs/272094 "2021-05-04T17:06:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![wmei](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wmei/32/88204_2.png) [@wmei](https://discuss.elastic.co/u/wmei)\
**Post date:** [May 4, 2021, 5:06pm UTC](https://discuss.elastic.co/t/logstash-date-filter-kibana-index-template-warning-in-logs/272094/1 "2021-05-04T17:06:55Z")

</div>

Hi,

Original log, these dates are in the format 20210504-15:40:02.601 and I have a date filter to convert that in my logstash.yml. I am doing the same filter for both the SendingTime and the TransactTime.

```
if [layers][fix][fix_fix_SendingTime] {
      date {
      # 20210426-17:47:27.052
      match => ["[layers][fix][fix_fix_SendingTime]", "yyyyMMdd-HH:mm:ss.SSS" ]
      target => "[layers][fix][fix_fix_SendingTime]"
      #target => "sendingtime"
      }
    }

```

I am trying to use an index template (7.10) to map a couple fields to date format. When I do that I get the error below but the field (SendingTime) looks like it did map correctly. As an example, I attached a picture of the TransactTime field which is still being classified by kibana as text.

 ![Screen Shot 2021-05-04 at 12.01.13 PM](https://us1.discourse-cdn.com/elastic/original/3X/2/8/28486781e70b309bf1371dd3bb118ad4abb52fab.png) ![Screen Shot 2021-05-04 at 12.01.24 PM](https://us1.discourse-cdn.com/elastic/original/3X/6/d/6d1761997fc4bf9232062df5eb019d80b2d8ed7e.png)

`[WARN] 2021-05-04 16:55:53.090 [[wei_pipeline_1]>worker0] elasticsearch - Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"fix-test-2021.05.04", :routing=>nil, :_type=>"_doc"}, #<LogStash::Event:0x6faab899>], :response=>{"index"=>{"_index"=>"fix-test-2021.05.04", "_type"=>"_doc", "_id"=>"dldOOHkBZU4iWKXXtezu", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [layers.fix.fix_fix_SendingTime] of type [date] in document with id 'dldOOHkBZU4iWKXXtezu'. Preview of field's value: '20210504-16:55:50.270'", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"failed to parse date field [20210504-16:55:50.270] with format [strict_date_optional_time||epoch_millis]", "caused_by"=>{"type"=>"date_time_parse_exception", "reason"=>"Failed to parse with all enclosed parsers"}}}}}}`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 4, 2021, 5:12pm UTC](https://discuss.elastic.co/t/logstash-date-filter-kibana-index-template-warning-in-logs/272094/2 "2021-05-04T17:12:14Z")

</div>

> [@wmei](#):
>
> "reason"=\>"failed to parse field [layers.fix.fix\_fix\_SendingTime] of type [date] in document with id 'dldOOHkBZU4iWKXXtezu'. Preview of field's value: '20210504-16:55:50.270'", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"failed to parse date field [20210504-16:55:50.270] with format [strict\_date\_optional\_time||epoch\_millis]",

That looks like it did not go through the date filter, since the date filter should have parsed and overwritten it.

---

<div class="post-metadata">

**Author:** ![wmei](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wmei/32/88204_2.png) [@wmei](https://discuss.elastic.co/u/wmei)\
**Post date:** [May 4, 2021, 5:43pm UTC](https://discuss.elastic.co/t/logstash-date-filter-kibana-index-template-warning-in-logs/272094/3 "2021-05-04T17:43:23Z")

</div>

Hi,

I used the add\_tag in the date plugin and can see the tags are applied.

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 1, 2021, 5:43pm UTC](https://discuss.elastic.co/t/logstash-date-filter-kibana-index-template-warning-in-logs/272094/4 "2021-06-01T17:43:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
