# Logstash, Date plugin not working as expected

**URL:** <https://discuss.elastic.co/t/logstash-date-plugin-not-working-as-expected/262525>\
**Category:** Logstash\
**Created:** [January 28, 2021, 3:12pm UTC](https://discuss.elastic.co/t/logstash-date-plugin-not-working-as-expected/262525 "2021-01-28T15:12:17Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sguerrero](https://avatars.discourse-cdn.com/v4/letter/s/87869e/32.png) [@sguerrero](https://discuss.elastic.co/u/sguerrero)\
**Post date:** [January 28, 2021, 3:12pm UTC](https://discuss.elastic.co/t/logstash-date-plugin-not-working-as-expected/262525/1 "2021-01-28T15:12:18Z")

</div>

Logstash Version: 7.10.1  
OS: Debian 10 Buster  
Architecture: x86-64  
Kernel: Linux 4.19.0-11-amd64

I'm trying to parse this date:

20210128 94501065

The pattern is:

```auto
      date {
         match => ["timestamp", "yyyyMMdd HmmssSSS"]
         target => "@timestamp"
      }

```

It fails.

```
          "timestamp" => "20210128 94501065",

```

"\_dateparsefailure"  
"@timestamp" =\> 2021-01-28T15:05:28.283Z,

But I noticed something interesting, if I modify the log to:

20210128 9:45:01.065

So the pattern will be:

```auto
      date {
         match => ["timestamp", "yyyyMMdd H:mm:ss.SSS"]
         target => "@timestamp"
      }

```

It succeed:

```
          "timestamp" => "20210128 9:45:01.065",
         "@timestamp" => 2021-01-28T12:45:01.065Z,

```

Date with 2 digits hour works fine:  
20210128 104501065

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [January 28, 2021, 3:43pm UTC](https://discuss.elastic.co/t/logstash-date-plugin-not-working-as-expected/262525/2 "2021-01-28T15:43:21Z")

</div>

Are you able to adjust the log to generate a full `hour`?

I am not sure how you would get a correct hour with only 1 digit. What would an example timestamp look like from your log for the afternoon hours?

```auto
 K hour of halfday (0~11) number 0
 h clockhour of halfday (1~12) number 12

 H hour of day (0~23) number 0
 k clockhour of day (1~24) number 24

```

---

<div class="post-metadata">

**Author:** ![sguerrero](https://avatars.discourse-cdn.com/v4/letter/s/87869e/32.png) [@sguerrero](https://discuss.elastic.co/u/sguerrero)\
**Post date:** [January 28, 2021, 4:41pm UTC](https://discuss.elastic.co/t/logstash-date-plugin-not-working-as-expected/262525/3 "2021-01-28T16:41:02Z")

</div>

Thanks for your reply.  
Those logs are external I can't modify them.

For example afternoon:  
`125959416`

I'm reading this [https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html) and it said:

```auto
H

hour of the day (24-hour clock)

H
minimal-digit hour. Example: 0 for midnight.
HH
two-digit hour, zero-padded if needed. Example: 00 for midnight.

```

To my understanding H would match between 0 to 23, but it doesn't if there is not a separator between hours, minutes, seconds and milliseconds (but it does match if I have separatos like H:mm:ss.SSS). So I guess that the problem I'm having is related to the way that the H match the pattern when there is not a separator.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 28, 2021, 5:14pm UTC](https://discuss.elastic.co/t/logstash-date-plugin-not-working-as-expected/262525/4 "2021-01-28T17:14:48Z")

</div>

I think the problem is in the underlying Joda library that the date filter uses. When it sees H the builder [looks for](https://github.com/JodaOrg/joda-time/blob/890fb7b8801f7a8132464a8d558f410373918f96/src/main/java/org/joda/time/format/DateTimeFormatterBuilder.java#L726) one or two digits -- it is not limited to one. That will consume '94', which is not a valid hour.

You could use mutate+gsub to change the timestamp to "20210128 9.4501065" and then parse that using "yyyyMMdd H.mmssSSS"

---

<div class="post-metadata">

**Author:** ![sguerrero](https://avatars.discourse-cdn.com/v4/letter/s/87869e/32.png) [@sguerrero](https://discuss.elastic.co/u/sguerrero)\
**Post date:** [January 28, 2021, 6:14pm UTC](https://discuss.elastic.co/t/logstash-date-plugin-not-working-as-expected/262525/5 "2021-01-28T18:14:38Z")

</div>

Thank you very much!

I'm doing something like this:

```auto
      if [hour_field] =~ /^\d{8}$/ {
         mutate {
            replace => { "hour_field" => "0%{hour_field}" }
         }
      }

```

I have two fields, first one is the date 20210128, second one is the time, 94501065

yyyyMMdd HHmmssSSS

So far it's working properly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 25, 2021, 6:14pm UTC](https://discuss.elastic.co/t/logstash-date-plugin-not-working-as-expected/262525/6 "2021-02-25T18:14:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
