# Logstash date formatting

**URL:** <https://discuss.elastic.co/t/logstash-date-formatting/145767>\
**Category:** Logstash\
**Created:** [August 23, 2018, 3:02pm UTC](https://discuss.elastic.co/t/logstash-date-formatting/145767 "2018-08-23T15:02:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![pastechecker](https://avatars.discourse-cdn.com/v4/letter/p/0ea827/32.png) [@pastechecker](https://discuss.elastic.co/u/pastechecker)\
**Post date:** [August 23, 2018, 3:02pm UTC](https://discuss.elastic.co/t/logstash-date-formatting/145767/1 "2018-08-23T15:02:40Z")

</div>

Hello.  
I have following loglines:

> Aug 22 10:19:48 s1435 postfix/smtp[17330]: 28C1328124A4: to=[jacobsd@gmail.com](mailto:jacobsd@gmail.com), [relay=smtp2.google.com](http://relay=smtp2.google.com)[194.14.9.134]:25, delay=1100, delays=0/1100/0.13/0.26, dsn=2.0.0, status=sent (250 2.0.0 Ok: queued as 4FDD469A41\_B7D1CA4F)

My filter is:

> input {  
> file {  
> path =\> "/etc/logstash/conf.d/myfile.log"  
> start\_position =\> "beginning"  
> }  
> }
> 
> filter {  
> grok {  
> match =\> { "message" =\> "^%{SYSLOGTIMESTAMP}\s%{DATA}\<%{DATA:email}\>%{GREEDYDATA}" }  
> }  
> }

Is there a way to use this syslogtimestamp as a @timestamp to use the upper-right time filtering capability in Kibana?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 23, 2018, 6:23pm UTC](https://discuss.elastic.co/t/logstash-date-formatting/145767/2 "2018-08-23T18:23:20Z")

</div>

Yes, use a date filter. See [https://www.elastic.co/guide/en/logstash/current/config-examples.html](https://www.elastic.co/guide/en/logstash/current/config-examples.html) for an example.

Your grok expression is inefficient and potentially buggy. Don't use more than one DATA or GREEDYDATA pattern in the same expression.

---

<div class="post-metadata">

**Author:** ![pastechecker](https://avatars.discourse-cdn.com/v4/letter/p/0ea827/32.png) [@pastechecker](https://discuss.elastic.co/u/pastechecker)\
**Post date:** [August 24, 2018, 9:15am UTC](https://discuss.elastic.co/t/logstash-date-formatting/145767/3 "2018-08-24T09:15:10Z")

</div>

Thanks for the hint.

Working configuration is:

filter {  
grok { match =\> { "message" =\> "^%{SYSLOGTIMESTAMP:logdate} %{DATA:direction} %{DATA:email\_address}$" }}  
date {  
match =\> ["logdate", "MMM dd HH:mm:ss"]  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2018, 9:15am UTC](https://discuss.elastic.co/t/logstash-date-formatting/145767/4 "2018-09-21T09:15:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
