# Logstash date to datetime format

**URL:** <https://discuss.elastic.co/t/logstash-date-to-datetime-format/221446>\
**Category:** Logstash\
**Created:** [February 28, 2020, 2:07pm UTC](https://discuss.elastic.co/t/logstash-date-to-datetime-format/221446 "2020-02-28T14:07:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![michal\_mastro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michal_mastro/32/55253_2.png) [@michal\_mastro](https://discuss.elastic.co/u/michal_mastro)\
**Post date:** [February 28, 2020, 2:07pm UTC](https://discuss.elastic.co/t/logstash-date-to-datetime-format/221446/1 "2020-02-28T14:07:21Z")

</div>

Hi,

Im using logstash to get data from mysql and pass them to elasticsearch.  
Unfortunately date format is default parsed to zulu time. In need get data in datetime format  
like `yyyy-mm-dd H:i:s` without t and z. Below is my logstash config

`input {  
jdbc {  
jdbc\_driver\_library =\> "/etc/mysql/driver/mysql-connector-java-5.1.48/mysql-connector-java-5.1.48-bin.jar"  
jdbc\_driver\_class =\> "com.mysql.jdbc.Driver"  
jdbc\_connection\_string =\> "jdbc:mysql://localhost:3306/db"  
jdbc\_user =\> root  
jdbc\_password =\> "secret"  
tracking\_column =\> "id"  
use\_column\_value=\> true  
statement =\> "SELECT \* FROM db.logs;"  
schedule =\> " \* \* \* \* \* \*"  
}

}

output {  
elasticsearch {  
document\_id=\> "%{id}"  
document\_type =\> "\_doc"  
index =\> "logs"  
hosts =\> "[http://localhost:9200](http://localhost:9200)"  
sniffing =\> true  
}

stdout{  
codec =\> rubydebug  
}  
}

filter {

date {  
match =\> ["date", "yyyy-MM-dd HH:mm:ss"]  
}  
}`

In this case i received "\_dateparsefailure".  
Im also tried with mutate gsub and convert but not successed. Please help

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 28, 2020, 5:37pm UTC](https://discuss.elastic.co/t/logstash-date-to-datetime-format/221446/2 "2020-02-28T17:37:28Z")

</div>

If date is already a LogStash::Timestamp you can [use ruby and strftime](https://discuss.elastic.co/t/date-field-being-converted-to-timestamps/180044/4) to format it as any string format you like.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [February 28, 2020, 7:55pm UTC](https://discuss.elastic.co/t/logstash-date-to-datetime-format/221446/3 "2020-02-28T19:55:44Z")

</div>

here is syntax. search on it and you will find it more  
setting up new date\_time from old value  
Also you have syntax wrong on date

```
date {
    match => ["date", "yyyy-MM-dd HH:mm:ss"]
    target => "date"
}

ruby {
    code => "
      event.set('date_time', event.get('date').time.localtime.strftime('%Y-%m-%d %H:%M:%S'))
    "
  }

```

you can use grok to convert that in to seperate field.

grok { match =\> { "date\_time" =\> "^%{YEAR:year}-%{MONTHNUM2:month}-%{MONTHDAY:day}" } }

```
    and you will have three new field, year,month,day
and you can join them if you want string date not date format

mutate { 
   add_field => { "testdate" => "%{year}-%{month}-%{day} } 
  }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2020, 7:55pm UTC](https://discuss.elastic.co/t/logstash-date-to-datetime-format/221446/4 "2020-03-27T19:55:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
