# Logstash Date parsing (with AM/PM data) for YYYY-MM-dd HH:mm:ss,SSS format

**URL:** https://discuss.elastic.co/t/logstash-date-parsing-with-am-pm-data-for-yyyy-mm-dd-hhss-sss-format/186094
**Category:** Logstash
**Created:** [June 17, 2019, 2:41pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-with-am-pm-data-for-yyyy-mm-dd-hhss-sss-format/186094 "2019-06-17T14:41:49Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![abinashkd](https://avatars.discourse-cdn.com/v4/letter/a/a9a28c/32.png) [@abinashkd](https://discuss.elastic.co/u/abinashkd)
#### Post date: [June 17, 2019, 2:41pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-with-am-pm-data-for-yyyy-mm-dd-hhss-sss-format/186094/1 "2019-06-17T14:41:50Z")

</div>

Hi,  
I am new to logstash. With some R&D I have written a grok, but don't weather it validates or not.

Input:  
####\<Jun 17, 2019 1:33:20 PM GMT\>

Output:  
I need the date in the format of 2019-06-17T13:33:20.000Z in ES.  
Basically if the timestamp is in PM format then add 12 hrs. Like above time was 1PM , and I need the o/p as 13.

My Prog:

grok {  
match =\> { "message" =\> "####\<%{MONTH:month} %{MONTHDAY:day}, %{YEAR:year} %{TIME:time} %{DATA:ampm} %{DATA:gmt}\> %{GREEDYDATA:errormessage}" }  
}  
if[ampm == "PM"]{  
time=time+12  
}  
mutate {  
add\_field =\> { "eventTimestamp" =\> "%{year}-%{month}-%{day} %{time}" }  
}  
date {  
match =\> ["eventTimestamp", "YYYY-MM-dd HH:mm:ss,SSS"]  
timezone =\> "UTC"  
target =\> "eventTimestamp"  
}

Question: So will this block would suffice ""if[ampm == "PM"]"".

Thanks in advance for any kind of help.

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [June 17, 2019, 2:57pm UTC](https://discuss.elastic.co/t/logstash-date-parsing-with-am-pm-data-for-yyyy-mm-dd-hhss-sss-format/186094/2 "2019-06-17T14:57:18Z")

</div>

> [@abinashkd](#):
>
> ####\<Jun 17, 2019 1:33:20 PM GMT\>

A date filter will parse this provided you use hh for the hour

```
grok { match => { "message" => "^####<%{DATA:[@metadata][ts]}>$" } }
date { match => ["[@metadata][ts]", "MMM dd, YYYY hh:mm:ss a ZZZ" ] }

```

In your configuration "time = time + 12" will not do what you want.

Note that dd and hh will both match either one or two digits.

---

<div class="post-metadata">

### Author: ![abinashkd](https://avatars.discourse-cdn.com/v4/letter/a/a9a28c/32.png) [@abinashkd](https://discuss.elastic.co/u/abinashkd)
#### Post date: [June 20, 2019, 9:49am UTC](https://discuss.elastic.co/t/logstash-date-parsing-with-am-pm-data-for-yyyy-mm-dd-hhss-sss-format/186094/3 "2019-06-20T09:49:29Z")

</div>

When I start the log-stash it is giving JSON parser failure for this pattern.

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [June 20, 2019, 11:09am UTC](https://discuss.elastic.co/t/logstash-date-parsing-with-am-pm-data-for-yyyy-mm-dd-hhss-sss-format/186094/4 "2019-06-20T11:09:43Z")

</div>

There is no mention of JSON in this thread, so there is no way for us to understand why that might happen unless you show us the configuration and the data.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 18, 2019, 11:09am UTC](https://discuss.elastic.co/t/logstash-date-parsing-with-am-pm-data-for-yyyy-mm-dd-hhss-sss-format/186094/5 "2019-07-18T11:09:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
