# Logstash date parse failure for jdbc input

**URL:** <https://discuss.elastic.co/t/logstash-date-parse-failure-for-jdbc-input/92713>\
**Category:** Logstash\
**Created:** [July 11, 2017, 8:08pm UTC](https://discuss.elastic.co/t/logstash-date-parse-failure-for-jdbc-input/92713 "2017-07-11T20:08:53Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bernie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bernie/32/45778_2.png) [@Bernie](https://discuss.elastic.co/u/Bernie)\
**Post date:** [July 11, 2017, 8:08pm UTC](https://discuss.elastic.co/t/logstash-date-parse-failure-for-jdbc-input/92713/1 "2017-07-11T20:08:53Z")

</div>

Hi there,

I currently encounter a strange problem while trying to get my Oracle-\>ES transfer working.

Input is pretty much only jdbc and a "select event\_timestamp from table" where the column in the database is a "TIMESTAMP WITH TIME ZONE"

My filter looks like this:

```
date
{
    match => ["event_timestamp", "ISO8601"]
}

```

but for whatever kind of reason, I get consistent dateparsefailures, where I'm under the impression that event\_timestamp pretty much matches the ISO8601 format?

```
{
         "@timestamp" => 2017-07-10T15:30:05.072Z,
           "@version" => "1",
    "event_timestamp" => 2017-07-06T14:13:14.555Z,
               "tags" => [
        [0] "_dateparsefailure"
    ]
}

```

Is there any way to debug the date parser?

regards,  
Bernhard

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 12, 2017, 3:59pm UTC](https://discuss.elastic.co/t/logstash-date-parse-failure-for-jdbc-input/92713/2 "2017-07-12T15:59:09Z")

</div>

This exact topic was discussed in a thread that was active yesterday or possibly the day before that. Please see the archives.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 12, 2017, 4:02pm UTC](https://discuss.elastic.co/t/logstash-date-parse-failure-for-jdbc-input/92713/3 "2017-07-12T16:02:27Z")

</div>

This issue contains links to previous threads:

> <https://github.com/logstash-plugins/logstash-filter-date/issues/95>

---

<div class="post-metadata">

**Author:** ![Bernie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bernie/32/45778_2.png) [@Bernie](https://discuss.elastic.co/u/Bernie)\
**Post date:** [July 12, 2017, 5:19pm UTC](https://discuss.elastic.co/t/logstash-date-parse-failure-for-jdbc-input/92713/4 "2017-07-12T17:19:35Z")

</div>

thanks, I don't know why I haven't found those threads when I used the search function.

---

<div class="post-metadata">

**Author:** ![Bernie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bernie/32/45778_2.png) [@Bernie](https://discuss.elastic.co/u/Bernie)\
**Post date:** [July 13, 2017, 11:37am UTC](https://discuss.elastic.co/t/logstash-date-parse-failure-for-jdbc-input/92713/5 "2017-07-13T11:37:10Z")

</div>

the solution is to create a new field from the timestamp, which is then a string, which can be parsed by the date filter...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2017, 11:37am UTC](https://discuss.elastic.co/t/logstash-date-parse-failure-for-jdbc-input/92713/6 "2017-08-10T11:37:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
