# Logstash date parse issue with date filter using csv file input plugin

**URL:** <https://discuss.elastic.co/t/logstash-date-parse-issue-with-date-filter-using-csv-file-input-plugin/350850>\
**Category:** Logstash\
**Created:** [January 11, 2024, 11:23am UTC](https://discuss.elastic.co/t/logstash-date-parse-issue-with-date-filter-using-csv-file-input-plugin/350850 "2024-01-11T11:23:30Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jgregory\_tc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jgregory_tc/32/126270_2.png) [@jgregory\_tc](https://discuss.elastic.co/u/jgregory_tc)\
**Post date:** [January 11, 2024, 11:23am UTC](https://discuss.elastic.co/t/logstash-date-parse-issue-with-date-filter-using-csv-file-input-plugin/350850/1 "2024-01-11T11:23:30Z")

</div>

Hoping someone can assist me with my issue below:

I have Logstash conf setup to use the csv input plugin. The data inputs a date field with value like follows…

2024-01-09 22:21:04

I then have this logic in the filter plugin to handle the date…

```auto
  date {
    match => ["cart_received_timestamp", "yyyy-MM-dd HH:mm:ss", "yyyy-MM-dd'T'HH:mm:ss.SSS'Z'"]
    target => "@timestamp"
  }

```

I am getting the following error (I’m using strict in my index to reject invalid data). The input date-

2024-01-09 22:21:04

… and the index expectation-

yyyy-MM-dd HH:mm:ss||yyyy-MM-dd'T'HH:mm:ss.SSS'Z'

… are the same.

It seems like logstash converts my date to the format below:

'2024-01-09T22:21:04.567414642Z'

… causing the error as it does not match the index mapping for this field’s required format.

```auto
{"update"=>{"status"=>400, "error"=>{"type"=>"document_parsing_exception", "reason"=>"[1:539] failed to parse field [@timestamp] of type [date] in document with id 'punchout_cart_item_182439'. Preview of field's value: '2024-01-09T22:21:04.567414642Z'", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"failed to parse date field [2024-01-09T22:21:04.567414642Z] with format [yyyy-MM-dd HH:mm:ss||yyyy-MM-dd'T'HH:mm:ss.SSS'Z']", "caused_by"=>{"type"=>"date_time_parse_exception", "reason"=>"Failed to parse with all enclosed parsers"}

```

I’ve tried various changes to the format in the conf file (like ISO8601, adding the convert option to change the field to date\_time, ChatGPT recommended some ruby option with code the change the date format … none changed the error condition.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 8, 2024, 11:23am UTC](https://discuss.elastic.co/t/logstash-date-parse-issue-with-date-filter-using-csv-file-input-plugin/350850/2 "2024-02-08T11:23:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
