# Logstash - Date function - Mapping timestamp ends with error \_dateparsefailure when a hour is 02

**URL:** <https://discuss.elastic.co/t/logstash-date-function-mapping-timestamp-ends-with-error-dateparsefailure-when-a-hour-is-02/227679>\
**Category:** Logstash\
**Created:** [April 12, 2020, 2:39pm UTC](https://discuss.elastic.co/t/logstash-date-function-mapping-timestamp-ends-with-error-dateparsefailure-when-a-hour-is-02/227679 "2020-04-12T14:39:10Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 12, 2020, 5:12pm UTC](https://discuss.elastic.co/t/logstash-date-function-mapping-timestamp-ends-with-error-dateparsefailure-when-a-hour-is-02/227679/5 "2020-04-12T17:12:08Z")

</div>

> [@vasek](#):
>
> So how we can achieve to correctly map this dates?

When I have dealt with this in the past (when analyzing NYPD arrest records) I used a series of gsubs

```
mutate { gsub => ["someField", "^2020-03-29 02:", "2020-03-29 03:"] }

```

That only deals with the one hour. When your logs contain "2020-03-29 03:35:47.392" they may well mean "2020-03-29 04:35:47.392". It also ignores the problems when time goes back later in the year. Personally I only cared whether arrests were recorded in the right month, so an hour with twice as many events as it should have had, and an hour that had no events did not bother me.

---

_[View the full topic](https://discuss.elastic.co/t/logstash-date-function-mapping-timestamp-ends-with-error-dateparsefailure-when-a-hour-is-02/227679)._
