# Logstash date parsing and convert

**URL:** <https://discuss.elastic.co/t/logstash-date-parsing-and-convert/219012>\
**Category:** Logstash\
**Created:** [February 12, 2020, 2:28pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-and-convert/219012 "2020-02-12T14:28:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pawel\_Mazurek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pawel_mazurek/32/47685_2.png) [@Pawel\_Mazurek](https://discuss.elastic.co/u/Pawel_Mazurek)\
**Post date:** [February 12, 2020, 2:28pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-and-convert/219012/1 "2020-02-12T14:28:18Z")

</div>

Hi  
I have some issue with proper parsing string with date value.

In my log i have timestamp like this =\> Mon, 10 Feb 2020 09:22:04 CET

Now i want to parse this values and create some string field and after all i want to convert it to date field.

So i have filter like this below

> filter  
> {  
> if "int\_prod\_MessageLogger" in [log][file][path]  
> {  
> grok {  
> match =\> { "message" =\> "(?\<system\_timestamp\>[A-z]{3},\s[0-9]{1,2}\s[A-z]{3}\s\d{4}\s%{TIME}\s[A-Z]{1,5})"}  
> }  
> }  
> date {  
> match =\> ["ystem\_timestamp", "EEE, dd MMM yyyy hh:mm:ss z"]  
> #\_system\_timestamp" =\> "Mon, 10 Feb 2020 09:16:00 CET"  
> target =\> "@timestamp"  
> timezone=\>"Europe/Warsaw"  
> }  
> }

I tried to parse with or withoute timezone set but still not works at all.

My goal is to to have it this timevalue as a main time index in elastic.

I will be grateful for any hints.

Best Regards

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 12, 2020, 3:00pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-and-convert/219012/2 "2020-02-12T15:00:31Z")

</div>

> [@Pawel\_Mazurek](#):
>
> [A-z]

You probably want to use [A-Za-z] rather than [A-z], since the upper and lower case letters are not contiguous blocks.

Also

```
match => ["ystem_timestamp", "EEE, dd MMM yyyy hh:mm:ss z"]

```

That should be system\_timestamp, not ystem\_timestamp.

---

<div class="post-metadata">

**Author:** ![Pawel\_Mazurek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pawel_mazurek/32/47685_2.png) [@Pawel\_Mazurek](https://discuss.elastic.co/u/Pawel_Mazurek)\
**Post date:** [February 12, 2020, 3:09pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-and-convert/219012/3 "2020-02-12T15:09:27Z")

</div>

> [@Badger](#):
>
> > [@Pawel\_Mazurek](#):
> >
> > [A-z]
> 
> You probably want to use [A-Za-z] rather than [A-z], since the upper and lower case letters are not contiguous blocks.
> 
> Also
> 
> ```
> match => ["ystem_timestamp", "EEE, dd MMM yyyy hh:mm:ss z"]
> 
> ```
> 
> That should be system\_timestamp, not ystem\_timestamp.

Yeah this is a copy paste error. My original (not working config ;)) has a system\_timestamp.  
Plus i corrected regexp and still have a dateparsefailure :(.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 11, 2020, 3:09pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-and-convert/219012/4 "2020-03-11T15:09:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
