# Logstash Date Type

**URL:** <https://discuss.elastic.co/t/logstash-date-type/78637>\
**Category:** Logstash\
**Created:** [March 15, 2017, 4:19am UTC](https://discuss.elastic.co/t/logstash-date-type/78637 "2017-03-15T04:19:06Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shubham\_Joshi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubham_joshi/32/16347_2.png) [@Shubham\_Joshi](https://discuss.elastic.co/u/Shubham_Joshi)\
**Post date:** [March 15, 2017, 4:19am UTC](https://discuss.elastic.co/t/logstash-date-type/78637/1 "2017-03-15T04:19:06Z")

</div>

I am using logstash to parse my logs on S3(gz).  
My log has data like:  
172.31.0.14 - - [15/May/2016:06:49:02 +0000] "GET /ottsale/youthstars.html?color=112&manufacturer=116&ram=384&utm\_campaign=mi\_2704&utm\_medium=post&utm\_source=facebook HTTP/1.1" 200 38513 "-" "Mozilla/5.0 (Windows NT 5.1; rv:6.0.2) Gecko/20100101 Firefox/6.0.2"

I am using grok parser as:  
%{IP:client} %{USERNAME} %{USERNAME} [%{HTTPDATE:log\_timestamp}] (?:"%{WORD:request} %{URIPATHPARAM:path} HTTP/%{NUMBER:version}" %{NUMBER:reponse:int} %{NUMBER:bytes} "%{USERNAME}" %{GREEDYDATA:responseMessage})

If i visualize my log in kibana it is showing log\_timestamp field as a string.I would like use this as timestamp.Please help.

I have also used filter in logstash conf file as but its not helping.  
filter {

```
    if [type] == "s3" {
            grok {
                    match => { "message" => "%{NGINXACCESS}" }
                            patterns_dir => ["/opt/logstash/pattterns"]

```

}

date {  
match =\> ["log\_timestamp" ,"dd/MMM/yyyy:HH:mm:ss Z"]  
}

```
    }
    }
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 15, 2017, 6:29am UTC](https://discuss.elastic.co/t/logstash-date-type/78637/2 "2017-03-15T06:29:13Z")

</div>

Unless told otherwise the date filter stores the parsed timestamp in the `@timestamp` field. Does that field contain the correct data? If yes, just use that field and remove `log_timestamp` after you've parsed the date.

---

<div class="post-metadata">

**Author:** ![Shubham\_Joshi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubham_joshi/32/16347_2.png) [@Shubham\_Joshi](https://discuss.elastic.co/u/Shubham_Joshi)\
**Post date:** [March 15, 2017, 6:44am UTC](https://discuss.elastic.co/t/logstash-date-type/78637/3 "2017-03-15T06:44:58Z")

</div>

You want me to remove date filter here in conf.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 15, 2017, 6:46am UTC](https://discuss.elastic.co/t/logstash-date-type/78637/4 "2017-03-15T06:46:48Z")

</div>

No. Keep the date filter. Make sure it successfully parses `log_timestamp` into `@timestamp`. Delete the `log_timestamp` field.

---

<div class="post-metadata">

**Author:** ![Shubham\_Joshi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubham_joshi/32/16347_2.png) [@Shubham\_Joshi](https://discuss.elastic.co/u/Shubham_Joshi)\
**Post date:** [March 15, 2017, 6:48am UTC](https://discuss.elastic.co/t/logstash-date-type/78637/5 "2017-03-15T06:48:37Z")

</div>

Little [confused.It](http://confused.It) is creating @timestamp with the current time.I want my log time to be of type timstamp [type.It](http://type.It) is currently showing as string.

Is this you are taking about?  
date {  
match =\> ["@timestamp","dd/MMM/yyyy:HH:mm:ss Z"]  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 15, 2017, 7:05am UTC](https://discuss.elastic.co/t/logstash-date-type/78637/6 "2017-03-15T07:05:24Z")

</div>

> It is creating @timestamp with the current time.I want my log time to be of type timstamp type.

If `@timestamp` contains the current time rather than the time parsed from the `log_timestamp` field the date filter isn't working. Your event will have a `_dateparsefailure` tag and the Logstash log will contain details about the failure.

> It is currently showing as string.

How do you reach that conclusion?

> Is this you are taking about?

That's the date filter, yes.

---

<div class="post-metadata">

**Author:** ![Shubham\_Joshi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubham_joshi/32/16347_2.png) [@Shubham\_Joshi](https://discuss.elastic.co/u/Shubham_Joshi)\
**Post date:** [March 15, 2017, 7:25am UTC](https://discuss.elastic.co/t/logstash-date-type/78637/7 "2017-03-15T07:25:38Z")

</div>

I can see from kibana my log\_timestamp field is string where the inbuilt timestamp that logstash push is the only timestamp field. Can i have log\_timestamp as timestamp?  
Snapshot from kibana.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/e/5/e545fcc15d2e73e1e93f060e96504b8e2aa7361b.png)

---

<div class="post-metadata">

**Author:** ![Shubham\_Joshi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubham_joshi/32/16347_2.png) [@Shubham\_Joshi](https://discuss.elastic.co/u/Shubham_Joshi)\
**Post date:** [March 15, 2017, 8:11am UTC](https://discuss.elastic.co/t/logstash-date-type/78637/8 "2017-03-15T08:11:50Z")

</div>

This is what i am getting  
i want log\_timetamp to be datetime rather than string .

 ![](https://us1.discourse-cdn.com/elastic/original/3X/8/8/88eee823e4c54ee76861aeb7ccaef7270af0a69b.png)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 15, 2017, 8:18am UTC](https://discuss.elastic.co/t/logstash-date-type/78637/9 "2017-03-15T08:18:21Z")

</div>

> Can i have log\_timestamp as timestamp?

Yes, but I suggest you use the standard `@timestamp` field instead. As a beginner stick to the defaults.

---

<div class="post-metadata">

**Author:** ![Shubham\_Joshi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubham_joshi/32/16347_2.png) [@Shubham\_Joshi](https://discuss.elastic.co/u/Shubham_Joshi)\
**Post date:** [March 15, 2017, 8:57am UTC](https://discuss.elastic.co/t/logstash-date-type/78637/10 "2017-03-15T08:57:11Z")

</div>

But that will nor work because i want to plot log\_timestamp vs response graph not @timestamp vs response.  
This will give clear picture.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/8/b/8b58361b9d7d0de7df1f241cafb1ced2b3c0278d.png)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 15, 2017, 9:19am UTC](https://discuss.elastic.co/t/logstash-date-type/78637/11 "2017-03-15T09:19:23Z")

</div>

One more time: Fix your date filter. When your date filter works as intended the timestamp in `@timestamp` will be the same as `log_timestamp` and you won't need `log_timestamp` anymore.

---

<div class="post-metadata">

**Author:** ![Shubham\_Joshi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubham_joshi/32/16347_2.png) [@Shubham\_Joshi](https://discuss.elastic.co/u/Shubham_Joshi)\
**Post date:** [March 15, 2017, 9:21am UTC](https://discuss.elastic.co/t/logstash-date-type/78637/12 "2017-03-15T09:21:17Z")

</div>

here is my filter.

filter {

```
    if [type] == "s3" {
            grok {
                    match => { "message" => "%{NGINXACCESS}" }
                            patterns_dir => ["/opt/logstash/pattterns"]

```

}

date {  
match =\> ["@timestamp" ,"dd/MMM/yyyy:HH:mm:ss Z"]  
}

```
    }
    }
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 15, 2017, 9:22am UTC](https://discuss.elastic.co/t/logstash-date-type/78637/13 "2017-03-15T09:22:46Z")

</div>

> match =\> ["@timestamp" ,"dd/MMM/yyyy:HH:mm:ss Z"]

Not `@timestamp`. You want`log_timestamp` here. The field listed here is the name of the field you want to parse.

---

<div class="post-metadata">

**Author:** ![Shubham\_Joshi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubham_joshi/32/16347_2.png) [@Shubham\_Joshi](https://discuss.elastic.co/u/Shubham_Joshi)\
**Post date:** [March 15, 2017, 9:27am UTC](https://discuss.elastic.co/t/logstash-date-type/78637/14 "2017-03-15T09:27:20Z")

</div>

that is what i did initially which is not working.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 15, 2017, 9:42am UTC](https://discuss.elastic.co/t/logstash-date-type/78637/15 "2017-03-15T09:42:10Z")

</div>

If the date filter fails it will add a `_dateparsefailure` tag to the event and the Logstash log will contain details about the failure.

---

<div class="post-metadata">

**Author:** ![Shubham\_Joshi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubham_joshi/32/16347_2.png) [@Shubham\_Joshi](https://discuss.elastic.co/u/Shubham_Joshi)\
**Post date:** [March 15, 2017, 10:03am UTC](https://discuss.elastic.co/t/logstash-date-type/78637/16 "2017-03-15T10:03:20Z")

</div>

It is not failing.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 15, 2017, 10:08am UTC](https://discuss.elastic.co/t/logstash-date-type/78637/17 "2017-03-15T10:08:22Z")

</div>

Then it's either working as expected (which doesn't seem to be the case) or your date filter isn't actually used. Starting Logstash with `--log.level debug` and `--config.debug` may give additional clues about what's going on.

---

<div class="post-metadata">

**Author:** ![Shubham\_Joshi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubham_joshi/32/16347_2.png) [@Shubham\_Joshi](https://discuss.elastic.co/u/Shubham_Joshi)\
**Post date:** [March 15, 2017, 10:15am UTC](https://discuss.elastic.co/t/logstash-date-type/78637/18 "2017-03-15T10:15:23Z")

</div>

Running on debug mode still not getting error and data is being dumped on elastic search. Don't know what am i doing wrong dropped and created index again.Still getting same.

---

<div class="post-metadata">

**Author:** ![Shubham\_Joshi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubham_joshi/32/16347_2.png) [@Shubham\_Joshi](https://discuss.elastic.co/u/Shubham_Joshi)\
**Post date:** [March 15, 2017, 10:29am UTC](https://discuss.elastic.co/t/logstash-date-type/78637/19 "2017-03-15T10:29:44Z")

</div>

Event from debug:

output received {:event=\>{"message"=\>"172.31.26.87 - - [08/May/2016:09:05:51 +0000] "GET /accessories/type/speakers-docks.html?dir=asc&limit=20&manufacturer=116&mode=list&order=name HTTP/1.1" 200 32450 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"\n", "@version"=\>"1", "@timestamp"=\>"2016-05-08T09:05:51.000Z", "type"=\>"s3", "source"=\>"gzfiles", "client"=\>"172.31.26.87", "log\_timestamp"=\>"08/May/2016:09:05:51 +0000", "request"=\>"GET", "path"=\>"/accessories/type/speakers-docks.html?dir=asc&limit=20&manufacturer=116&mode=list&order=name", "version"=\>1, "response"=\>200, "bytes"=\>"32450", "responseMessage"=\>""Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"\n"}, :level=\>:debug, :file=\>"(eval)", :line=\>"73", :method=\>"output\_func"}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 15, 2017, 11:06am UTC](https://discuss.elastic.co/t/logstash-date-type/78637/20 "2017-03-15T11:06:57Z")

</div>

Okay, so the date filter is successful after all then. `log_timestamp` has successfully been parsed into `@timestamp`.

08/May/2016:09:05:51 +0000 \<=\> 2016-05-08T09:05:51.000Z

[Next page](https://discuss.elastic.co/t/logstash-date-type/78637.md?page=2)
