# Logstash - Date function - Mapping timestamp ends with error \_dateparsefailure when a hour is 02

**URL:** <https://discuss.elastic.co/t/logstash-date-function-mapping-timestamp-ends-with-error-dateparsefailure-when-a-hour-is-02/227679>\
**Category:** Logstash\
**Created:** [April 12, 2020, 2:39pm UTC](https://discuss.elastic.co/t/logstash-date-function-mapping-timestamp-ends-with-error-dateparsefailure-when-a-hour-is-02/227679 "2020-04-12T14:39:10Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![vasek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vasek/32/136636_2.png) [@vasek](https://discuss.elastic.co/u/vasek)\
**Post date:** [April 12, 2020, 2:39pm UTC](https://discuss.elastic.co/t/logstash-date-function-mapping-timestamp-ends-with-error-dateparsefailure-when-a-hour-is-02/227679/1 "2020-04-12T14:39:10Z")

</div>

Hello,  
I figured out one thing:  
Logstash 7.6.0 is not able map date to @timestamp field when timestamp has 02 in hour positio.

In pipeline configuration file:

```
if [timestamp] {
  date {
    match => ["timestamp", "yyyy-MM-dd HH:mm:ss,SSS", "yyyy-MM-dd HH:mm:ss.SSS", "ISO8601"]
    target => "@timestamp"
    remove_field => ["timestamp"]
  }
}

```

Grok pattern works fine. In the field `timestamp` is correct value, e.g.: **2020-03-29 03:35:47.392** without additional whitespaces.  
I simplified parser and date mapping and found out that error `_dateparsefailure` occur only on lines where hour is **02**.

```
2020-03-29 02:35:47.392 INFO [xxx] Some message

```

&nbsp;  
There is example of log file.

```
2020-03-29 15:35:47.392 INFO [xxx] Some message
2020-03-29 14:35:47.392 INFO [xxx] Some message
2020-03-29 13:35:47.392 INFO [xxx] Some message
2020-03-29 12:35:47.392 INFO [xxx] Some message
2020-03-29 11:35:47.392 INFO [xxx] Some message
2020-03-29 10:35:47.392 INFO [xxx] Some message
2020-03-29 09:35:47.392 INFO [xxx] Some message
2020-03-29 08:35:47.392 INFO [xxx] Some message
2020-03-29 07:35:47.392 INFO [xxx] Some message
2020-03-29 06:35:47.392 INFO [xxx] Some message
2020-03-29 05:35:47.392 INFO [xxx] Some message
2020-03-29 04:35:47.392 INFO [xxx] Some message
2020-03-29 03:35:47.392 INFO [xxx] Some message
2020-03-29 02:35:47.392 INFO [xxx] Some message
2020-03-29 01:35:47.392 INFO [xxx] Some message

```

**Is it a bug or am I doing something wrong?**  
Vašek

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 12, 2020, 3:38pm UTC](https://discuss.elastic.co/t/logstash-date-function-mapping-timestamp-ends-with-error-dateparsefailure-when-a-hour-is-02/227679/2 "2020-04-12T15:38:24Z")

</div>

Did 02:35 occur? Did daylight savings time cause the time to go directly from 01:59:59 to 03:00:00 that day?

---

<div class="post-metadata">

**Author:** ![vasek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vasek/32/136636_2.png) [@vasek](https://discuss.elastic.co/u/vasek)\
**Post date:** [April 12, 2020, 3:58pm UTC](https://discuss.elastic.co/t/logstash-date-function-mapping-timestamp-ends-with-error-dateparsefailure-when-a-hour-is-02/227679/3 "2020-04-12T15:58:33Z")

</div>

Hello @Badger, mapping fails on these 4 lines:

```
2020-03-29 02:06:54.462 INFO [liferay/scheduler_dispatch-4]
2020-03-29 02:07:09.545 INFO [liferay/scheduler_dispatch-4]
2020-03-29 02:35:47.392 INFO [default task-2]
2020-03-29 02:35:47.397 ERROR [default task-2]

```

Time in logs is in UTC. Our servers are in +1 UTC (Prague). But why would mapping fail?

---

<div class="post-metadata">

**Author:** ![vasek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vasek/32/136636_2.png) [@vasek](https://discuss.elastic.co/u/vasek)\
**Post date:** [April 12, 2020, 4:05pm UTC](https://discuss.elastic.co/t/logstash-date-function-mapping-timestamp-ends-with-error-dateparsefailure-when-a-hour-is-02/227679/4 "2020-04-12T16:05:05Z")

</div>

Aaa.. so it looks that problem is in daylight saving time change. Yes, the time should go to 03:00:00. So how we can achieve to correctly map this dates?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 12, 2020, 5:12pm UTC](https://discuss.elastic.co/t/logstash-date-function-mapping-timestamp-ends-with-error-dateparsefailure-when-a-hour-is-02/227679/5 "2020-04-12T17:12:08Z")

</div>

> [@vasek](#):
>
> So how we can achieve to correctly map this dates?

When I have dealt with this in the past (when analyzing NYPD arrest records) I used a series of gsubs

```
mutate { gsub => ["someField", "^2020-03-29 02:", "2020-03-29 03:"] }

```

That only deals with the one hour. When your logs contain "2020-03-29 03:35:47.392" they may well mean "2020-03-29 04:35:47.392". It also ignores the problems when time goes back later in the year. Personally I only cared whether arrests were recorded in the right month, so an hour with twice as many events as it should have had, and an hour that had no events did not bother me.

---

<div class="post-metadata">

**Author:** ![vasek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vasek/32/136636_2.png) [@vasek](https://discuss.elastic.co/u/vasek)\
**Post date:** [April 15, 2020, 5:43am UTC](https://discuss.elastic.co/t/logstash-date-function-mapping-timestamp-ends-with-error-dateparsefailure-when-a-hour-is-02/227679/6 "2020-04-15T05:43:16Z")

</div>

Thank you @Badger. It helps me.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 13, 2020, 5:43am UTC](https://discuss.elastic.co/t/logstash-date-function-mapping-timestamp-ends-with-error-dateparsefailure-when-a-hour-is-02/227679/7 "2020-05-13T05:43:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
