# Logstash Date Filter not working on Kibana

**URL:** <https://discuss.elastic.co/t/logstash-date-filter-not-working-on-kibana/245822>\
**Category:** Logstash\
**Created:** [August 20, 2020, 9:15pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-working-on-kibana/245822 "2020-08-20T21:15:31Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![userR](https://avatars.discourse-cdn.com/v4/letter/u/22d042/32.png) [@userR](https://discuss.elastic.co/u/userR)\
**Post date:** [August 20, 2020, 9:15pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-working-on-kibana/245822/1 "2020-08-20T21:15:31Z")

</div>

> date {  
> match =\> ["logdate", "YYYY.MM.dd HH:mm:ss,SSS"]  
> target =\> "logdate"  
> }

Above is my date filter configuration on my logstash config file. On kibana, when I create an index pattern, the only date option that shows up is @timestamp but not logdate.

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [August 20, 2020, 9:23pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-working-on-kibana/245822/2 "2020-08-20T21:23:57Z")

</div>

What is the mapping of logdate? Have a sample of the data?

---

<div class="post-metadata">

**Author:** ![userR](https://avatars.discourse-cdn.com/v4/letter/u/22d042/32.png) [@userR](https://discuss.elastic.co/u/userR)\
**Post date:** [August 21, 2020, 3:57pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-working-on-kibana/245822/3 "2020-08-21T15:57:29Z")

</div>

There is a logdate field which I believe parses correctly. Here is an example of the log time format: `2020-08-13 15:57:14,242`

```
Here is my config file below:
    input {
      beats {
        port => "5044"
        host => "0.0.0.0"
        ssl => false
      }
    }
    filter {
      grok {
        match => [
          #*grok patterns*
        ]
      }
      date {
        match => ["logdate", "YYYY.MM.dd HH:mm:ss,SSS"]
        target => "logdate"
      }
    }
    output {
      elasticsearch {
        hosts => ["*hosts*"]
        index => "logdata-%{+YYYY.MM.dd}"
      }
      stdout{}
    }
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 21, 2020, 4:00pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-working-on-kibana/245822/4 "2020-08-21T16:00:10Z")

</div>

What is the [mapping](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-mapping.html) for the field in elasticsearch? If is mapped as a string, then even if the date filter successfully parses it, elasticsearch will convert it from a Logstash::Timestamp to a string as it gets indexed.

---

<div class="post-metadata">

**Author:** ![userR](https://avatars.discourse-cdn.com/v4/letter/u/22d042/32.png) [@userR](https://discuss.elastic.co/u/userR)\
**Post date:** [August 21, 2020, 4:11pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-working-on-kibana/245822/5 "2020-08-21T16:11:34Z")

</div>

```
"logdate" : {
          "type" : "text",
          "fields" : {
            "keyword" : {
              "type" : "keyword",
              "ignore_above" : 256
            }
          }
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 21, 2020, 4:13pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-working-on-kibana/245822/6 "2020-08-21T16:13:58Z")

</div>

OK, so it is mapped as text. You will need to start over with a new index, if the date filter is working it will get mapped as a date/time. You could use an index template to force this mapping but probably will not need to.

---

<div class="post-metadata">

**Author:** ![userR](https://avatars.discourse-cdn.com/v4/letter/u/22d042/32.png) [@userR](https://discuss.elastic.co/u/userR)\
**Post date:** [August 21, 2020, 4:16pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-working-on-kibana/245822/7 "2020-08-21T16:16:49Z")

</div>

This is the 2nd index I have tried to use the date filter with, and in both cases logdate does not show up for time. How would I use the index template? I am not familiar with that.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 21, 2020, 4:31pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-working-on-kibana/245822/8 "2020-08-21T16:31:51Z")

</div>

It is documented [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-templates.html).

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [August 21, 2020, 4:46pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-working-on-kibana/245822/9 "2020-08-21T16:46:46Z")

</div>

> [@userR](#):
>
> ```auto
> date {
> match => ["logdate", "YYYY.MM.dd HH:mm:ss,SSS"]
> target => "logdate"
> }
> 
> ```

and your date is with -

2020-08-13 15:57:14,242

you need to change to YYYY-MM-dd

---

<div class="post-metadata">

**Author:** ![userR](https://avatars.discourse-cdn.com/v4/letter/u/22d042/32.png) [@userR](https://discuss.elastic.co/u/userR)\
**Post date:** [August 21, 2020, 4:52pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-working-on-kibana/245822/10 "2020-08-21T16:52:48Z")

</div>

Yep that's it, sorry for the trouble!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 18, 2020, 4:52pm UTC](https://discuss.elastic.co/t/logstash-date-filter-not-working-on-kibana/245822/11 "2020-09-18T16:52:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
