# Logstash Date Format Failure

**URL:** <https://discuss.elastic.co/t/logstash-date-format-failure/293702>\
**Category:** Logstash\
**Created:** [January 7, 2022, 2:46am UTC](https://discuss.elastic.co/t/logstash-date-format-failure/293702 "2022-01-07T02:46:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![insu0929](https://avatars.discourse-cdn.com/v4/letter/i/839c29/32.png) [@insu0929](https://discuss.elastic.co/u/insu0929)\
**Post date:** [January 7, 2022, 2:46am UTC](https://discuss.elastic.co/t/logstash-date-format-failure/293702/1 "2022-01-07T02:46:17Z")

</div>

Hi I'm using filebeat to send some session count data to Logstash. The file type is csv and the data looks like this:

```auto
...
"01/02/2022 00:00:27.837", "0.99961"
"01/02/2022 00:00:28.853", "0"
"01/02/2022 00:00:29.240", "1.005890494747181"
....

```

I wanted to parse this data into two columns named "date" and "count", then put each row as a document, so I could plot a timeline graph where the y-axis is "count" and x-axis is "date".  
So I tried to format the parsed "date" column to a timefield, but ran into a \_dateformatfailure.

Here's part of my logstash.conf file.

```auto
filter {
  if [fields][codex] == "web-session" {
     mutate {
       split => ["message", ","]
       add_field => {
         "date" => "%{[message][0]}"
         "count" => "%{[message][1]}"
        }
        remove_field => ["message"]
    }
    date {
      match => ["date", "MM/dd/YYYY HH:mm:ss.SSS"]
      timezone => "Asia/Seoul"
      target => "convert_date"
      remove_field => ["@timestamp"] 
    }

```

I used stdout to see how the parsed date field actually looked like, and found that it included quotation marks.

```auto
"date" => "\"01/02/2022 00:00:27.837"\"

```

I solved the problem by adding a gsub to delete the extra quotation marks, but my question is why did the date field contain extra quotation marks in the first place?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 7, 2022, 3:44am UTC](https://discuss.elastic.co/t/logstash-date-format-failure/293702/2 "2022-01-07T03:44:47Z")

</div>

> [@insu0929](#):
>
> I solved the problem by adding a gsub to delete the extra quotation marks, but my question is why did the date field contain extra quotation marks in the first place?

That is the solution I would have used.

Your message field `"01/02/2022 00:00:27.837", "0.99961"` is split into an array of two strings `["\"01/02/2022 00:00:27.837\"", " \"0.99961\""]`. Nothing in the filter is going to trim quotes or spaces unless you tell it to, and mutate+gsub is the way to do that here.

If you used a csv filter then that _would_ remove quotes around a field but I suspect the space after the comma will result in an invalid quoting exception -- the entire field including the leading space would have to be quoted.

---

<div class="post-metadata">

**Author:** ![insu0929](https://avatars.discourse-cdn.com/v4/letter/i/839c29/32.png) [@insu0929](https://discuss.elastic.co/u/insu0929)\
**Post date:** [January 7, 2022, 4:17am UTC](https://discuss.elastic.co/t/logstash-date-format-failure/293702/3 "2022-01-07T04:17:53Z")

</div>

@Badger  
Thanks for the reply.  
So I guess the reason was that the original csv file data already contained quotation marks which is unusual. I'm not very familiar with the csv file type so I reckoned having "" was normal. Thanks alot!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 4, 2022, 4:18am UTC](https://discuss.elastic.co/t/logstash-date-format-failure/293702/4 "2022-02-04T04:18:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
