# Logstash date filter not work

**URL:** https://discuss.elastic.co/t/logstash-date-filter-not-work/118454
**Category:** Logstash
**Created:** [February 5, 2018, 1:10pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-work/118454 "2018-02-05T13:10:10Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![uvali](https://avatars.discourse-cdn.com/v4/letter/u/ce73a5/32.png) [@uvali](https://discuss.elastic.co/u/uvali)
#### Post date: [February 5, 2018, 1:10pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-work/118454/1 "2018-02-05T13:10:10Z")

</div>

I try to use logstash date filter but it not work.

My conf is:  
input {  
stdin{}  
}

filter {  
date {  
match =\> ["when", "YYYY-MM-dd HH:mm:ss,SSS"]  
}  
grok {  
match =\> { "message" =\> "\ATID:%{SPACE}[%{INT:id}]%{SPACE}[(?([a-zA-Z0-9]_))]%{SPACE}[%{TIMESTAMP\_ISO8601:when}]%{SPACE}(?\<log\_level\>([a-zA-Z]_))\Z" }  
}  
}

output {  
stdout {  
codec =\> rubydebug  
}  
}

and I tested it in command file as:

echo "TID: [-1234] [] [2018-02-05 11:44:31,547] INFO" | /opt/logstash/bin/logstash -f /etc/logstash/conf.d/wso2.conf

I get this:  
Logstash startup completed  
{  
"message" =\> "TID: [-1234] [] [2018-02-05 11:44:31,547] INFO",  
"@version" =\> "1",  
"@timestamp" =\> "2018-02-05T13:06:08.946Z",  
"host" =\> "..................",  
"id" =\> "-1234",  
"when" =\> "2018-02-05 11:44:31,547",  
"log\_level" =\> "INFO"  
}  
Logstash shutdown completed

As you can see "@timestamp" is not replaced with "when".

Any idea?

Thanks

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [February 5, 2018, 1:44pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-work/118454/2 "2018-02-05T13:44:31Z")

</div>

Filters are evaluated in order. Your date filter must come after the grok filter.

---

<div class="post-metadata">

### Author: ![uvali](https://avatars.discourse-cdn.com/v4/letter/u/ce73a5/32.png) [@uvali](https://discuss.elastic.co/u/uvali)
#### Post date: [February 5, 2018, 1:56pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-work/118454/3 "2018-02-05T13:56:27Z")

</div>

Thank you very much. Now it works 😀

My new conf is:  
input {  
stdin{}  
}

filter {  
grok {  
match =\> { "message" =\> "\ATID:%{SPACE}[%{INT:id}]%{SPACE}[(?([a-zA-Z0-9]_))]%{SPACE}[%{TIMESTAMP\_ISO8601:when}]%{SPACE}(?\<log\_level\>([a-zA-Z]_))\Z" }  
}  
date {  
match =\> ["when", "YYYY-MM-dd HH:mm:ss,SSS"]  
}  
}

output {  
stdout {  
codec =\> rubydebug  
}  
}

and the results of:  
echo "TID: [-1234] [] [2018-02-05 11:44:32,548] INFO" | /opt/logstash/bin/logstash -f /etc/logstash/conf.d/wso2.conf

is:  
Settings: Default pipeline workers: 2  
Logstash startup completed  
{  
"message" =\> "TID: [-1234] [] [2018-02-05 11:44:32,548] INFO",  
"@version" =\> "1",  
"@timestamp" =\> "2018-02-05T09:44:32.548Z",  
"host" =\> "........",  
"id" =\> "-1234",  
"when" =\> "2018-02-05 11:44:32,548",  
"log\_level" =\> "INFO"  
}  
Logstash shutdown completed

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 5, 2018, 1:57pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-work/118454/4 "2018-03-05T13:57:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
