# Logstash Date parsing error

**URL:** <https://discuss.elastic.co/t/logstash-date-parsing-error/298780>\
**Category:** Logstash\
**Created:** [March 3, 2022, 6:32pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-error/298780 "2022-03-03T18:32:21Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![userR](https://avatars.discourse-cdn.com/v4/letter/u/22d042/32.png) [@userR](https://discuss.elastic.co/u/userR)\
**Post date:** [March 3, 2022, 6:32pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-error/298780/1 "2022-03-03T18:32:21Z")

</div>

Hi! I am trying to parse the following date format:

```auto
2022-03-03 10:45:02,520

```

My current configuration for logstash to parse is:

```auto
grok {
      match => [
        "message", "%{TIMESTAMP_ISO8601:logdate}....."
      ]
}
date {
      match => ["logdate", "YYYY-MM-dd HH:mm:ss,SSS"]
      target => "logdate"
}

```

However, when I view the logs on Kibana, I see the following logdate:

```auto
Mar 3, 2022 @ 02:45:02.520	

```

The hour field seems to be parsing incorrectly. I noticed on my grok debugger that TIMESTAMP\_ISO8601 parses the hour incorrectly but that shouldn't matter with my date pluggin right?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 3, 2022, 6:54pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-error/298780/2 "2022-03-03T18:54:56Z")

</div>

If you do not use the timezone option on the date filter it will parse assuming the field is in the logstash servers local timezone. The parsed time stored in Elasticsearch is always UTC.

Kibana will, by default, adjust the date to be in the browser's timezone.

Does that help?

---

<div class="post-metadata">

**Author:** ![userR](https://avatars.discourse-cdn.com/v4/letter/u/22d042/32.png) [@userR](https://discuss.elastic.co/u/userR)\
**Post date:** [March 3, 2022, 7:09pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-error/298780/3 "2022-03-03T19:09:30Z")

</div>

I'm still a little bit confused 😅

Logstash machine is on MST while the browsers timezone will be PST (1 hour behind). The log times are 7 hours behind for PST and 8 hours for MST.

Shouldn't my browser adjust the logdate so that they are in sync with PST?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 3, 2022, 7:29pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-error/298780/4 "2022-03-03T19:29:35Z")

</div>

It looks like Kibana is displaying the date in UTC. In the [advanced options](https://www.elastic.co/guide/en/kibana/current/advanced-options.html) of Kibana there is a dateFormat:tz option that controls what timezone it uses.

---

<div class="post-metadata">

**Author:** ![userR](https://avatars.discourse-cdn.com/v4/letter/u/22d042/32.png) [@userR](https://discuss.elastic.co/u/userR)\
**Post date:** [March 3, 2022, 9:35pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-error/298780/5 "2022-03-03T21:35:44Z")

</div>

I modified that field from "Browser" to US/Pacific". The logdate still seems to show the UTC time. I refreshed my browser, re-created Data Views and logged out and back in with no change.

Is there something I'm missing?

---

<div class="post-metadata">

**Author:** ![userR](https://avatars.discourse-cdn.com/v4/letter/u/22d042/32.png) [@userR](https://discuss.elastic.co/u/userR)\
**Post date:** [March 3, 2022, 9:59pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-error/298780/6 "2022-03-03T21:59:36Z")

</div>

I realized I mixed up some info. Both my Logstash and Elasticsearch machine are on PST. The machine with filebeat on it is MST

Additionally, @timestamp maps correctly, but logdate is 7 hours behind.

---

<div class="post-metadata">

**Author:** ![userR](https://avatars.discourse-cdn.com/v4/letter/u/22d042/32.png) [@userR](https://discuss.elastic.co/u/userR)\
**Post date:** [March 4, 2022, 7:15pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-error/298780/7 "2022-03-04T19:15:21Z")

</div>

Apologies for being a bit confusing but I'm still a little confused on what to do.

My pipeline (Filebeat 8.0.1 and Logstash/ES/Kibana 8.0.0):  
Filebeat machine (MST)  
Logstash Machine - Docker container (PST)  
ES Machine Docker container (PST)

Adjusting the Kibana settings to Pacific did not change anything for my 'logdate' field. So I suspect this is an issue with Logstash?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 4, 2022, 7:51pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-error/298780/8 "2022-03-04T19:51:30Z")

</div>

You should check what the value is in Elasticsearch. Fetch the document using curl, or with the [Dev Tools console](https://www.elastic.co/guide/en/kibana/current/console-kibana.html).

Also, check the [mappin](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-mapping.html)g for the field.

---

<div class="post-metadata">

**Author:** ![userR](https://avatars.discourse-cdn.com/v4/letter/u/22d042/32.png) [@userR](https://discuss.elastic.co/u/userR)\
**Post date:** [March 4, 2022, 8:38pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-error/298780/9 "2022-03-04T20:38:09Z")

</div>

Looks like Elasticsearch maps it correctly

```auto
          "event" : {
            "original" : "2022-03-03 16:55:02,521 ..."
          },
          "logdate" : "2022-03-03T16:55:02.521Z",

```

However the timestamp is:

```auto
          "@timestamp" : "2022-03-03T23:55:09.474Z",

```

And indice mapping:

```auto
        "logdate" : {
          "type" : "date"

```

---

<div class="post-metadata">

**Author:** ![userR](https://avatars.discourse-cdn.com/v4/letter/u/22d042/32.png) [@userR](https://discuss.elastic.co/u/userR)\
**Post date:** [March 4, 2022, 8:57pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-error/298780/10 "2022-03-04T20:57:14Z")

</div>

So the logs were created at 16:55:02.521. So 15:55:02 PST, but the timestamp shows 23:55:09

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 4, 2022, 9:48pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-error/298780/11 "2022-03-04T21:48:02Z")

</div>

So logdate exactly matches the start of [event][original]. That suggests that the date filter parser set the timezone to UTC. It is documented as using the system default timezone if the option is not set.

---

<div class="post-metadata">

**Author:** ![userR](https://avatars.discourse-cdn.com/v4/letter/u/22d042/32.png) [@userR](https://discuss.elastic.co/u/userR)\
**Post date:** [March 4, 2022, 10:11pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-error/298780/12 "2022-03-04T22:11:27Z")

</div>

> [@Badger](#):
>
> date filter parser set the timezone to UTC

I think I'm starting to understand. So I'll need to specify the time zone in my logstash config file. And since the server that it's reading logs from is MST, I'll need to specify

```auto
timezone => "MST"

```

Yup, this worked! Thanks Badger.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 1, 2022, 10:11pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-error/298780/13 "2022-04-01T22:11:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
