# Logstash \_dateparsefailure

**URL:** <https://discuss.elastic.co/t/logstash-dateparsefailure/142795>\
**Category:** Logstash\
**Created:** [August 2, 2018, 5:50pm UTC](https://discuss.elastic.co/t/logstash-dateparsefailure/142795 "2018-08-02T17:50:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sebastian\_Herrera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebastian_herrera/32/53209_2.png) [@Sebastian\_Herrera](https://discuss.elastic.co/u/Sebastian_Herrera)\
**Post date:** [August 2, 2018, 5:50pm UTC](https://discuss.elastic.co/t/logstash-dateparsefailure/142795/1 "2018-08-02T17:50:56Z")

</div>

Hello, i am trying to use date filter but i am getting \_dateparsefailure can anyone help me?

Log:  
{  
"timestamp": "Aug 2 10:47:59",  
"@timestamp": "2018-08-02T17:47:59.000Z",  
"timezone": "US/Pacific",  
"tags": [  
"syslog",  
"\_dateparsefailure"  
]  
},  
"fields": {  
"@timestamp": [  
"2018-08-02T17:47:59.000Z"  
]  
},  
"sort": [  
1533232079000  
]  
}

Config  
filter{  
date{  
match =\> ["timestamp", "MMM dd yyyy HH:mm:ss", "MMM d yyyy HH:mm:ss"]  
timezone =\> "US/Pacific"  
}  
}

regards

---

<div class="post-metadata">

**Author:** ![NerdSec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nerdsec/32/22056_2.png) [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Post date:** [August 2, 2018, 6:01pm UTC](https://discuss.elastic.co/t/logstash-dateparsefailure/142795/2 "2018-08-02T18:01:06Z")

</div>

Hi Sebastian,

I have the exact same date format and the following config works for me:

```auto
date {
      match => ["[event][timestamp]", "MMM dd HH:mm:ss" ]
      target => "[event][timestamp]"
    }

```

As the timestamp is already generated for my timezone, i don't specify it explicitly.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 2, 2018, 6:37pm UTC](https://discuss.elastic.co/t/logstash-dateparsefailure/142795/3 "2018-08-02T18:37:49Z")

</div>

Are there as many spaces between "Aug" and "2" and between "MMM" and "d"?

If the date filter fails it'll log a message containing clues about the nature of the error.

---

<div class="post-metadata">

**Author:** ![TechGeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/techgeek/32/28158_2.png) [@TechGeek](https://discuss.elastic.co/u/TechGeek)\
**Post date:** [August 3, 2018, 4:57am UTC](https://discuss.elastic.co/t/logstash-dateparsefailure/142795/4 "2018-08-03T04:57:01Z")

</div>

@magnusbaeck

I am trying to parse the 5/1/2018 7:48:00 AM with following filter code in logstash and want to convert it into Hing Kong timezone.

```
date{
            match=>["SUBMIT_DATE","M/d/yyyy H:mm:ss"]
            target => "SUBMIT_DATE"
			timezone => "Etc/GMT-7"
	} 

```

Q1- Does ELK support the date format with "/".  
Q2- My .csv recevie dates in "/" format, do I always need to change to "-" format.

Thanks for you help..  
Cheers !!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 31, 2018, 4:57am UTC](https://discuss.elastic.co/t/logstash-dateparsefailure/142795/5 "2018-08-31T04:57:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
