# Logstash: error when use date filter

**URL:** <https://discuss.elastic.co/t/logstash-error-when-use-date-filter/257517>\
**Category:** Logstash\
**Created:** [December 3, 2020, 1:32pm UTC](https://discuss.elastic.co/t/logstash-error-when-use-date-filter/257517 "2020-12-03T13:32:54Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![raistlin2912](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raistlin2912/32/80178_2.png) [@raistlin2912](https://discuss.elastic.co/u/raistlin2912)\
**Post date:** [December 3, 2020, 1:32pm UTC](https://discuss.elastic.co/t/logstash-error-when-use-date-filter/257517/1 "2020-12-03T13:32:54Z")

</div>

Hi, I'm setting up an ELK Stack to process some logs that are sent to us from AKAMAI. An example line:

> 2020-11-18 14:58:27 2.17.200.11 - - - - GET /unaurl.es/N3X3QDOPYNHGPO5R6ZYCEOWCNM.png - 200 1 36513 848 1 80 HTTP/1.1 "Mozilla/5.0 (X11; U; Linux x86\_64; en-US) AkamaiImageServer VelocitudeMP/1.0;IM/1.0" "-" "-"

Config file:

```auto
input {
    file {
        path => "/var/data/logs/*"
        start_position => "beginning"
        sincedb_path => "/dev/null"
    }
}

filter {
    grok {
        patterns_dir => ["/etc/logstash/conf.d/patterns"]
        match => {
            "message" => "%{TIMESTAMP_ISO8601:timestamp} %{IPV4:c-ip} %{USERNAME:cs-username} %{DATA:s-sitename} %{DATA:s-computername} %{CUSTOMIP:s-ip} %{WORD:cs-method} %{URIPATH:cs-uri-stem} %{CUSTOMURIPATH:cs-uri-query} %{NUMBER:sc-status} %{NUMBER:sc-win32-status} %{NUMBER:sc-bytes} %{NUMBER:cs-bytes} %{NUMBER:time-taken} %{CUSTOMPORT:s-port} %{DATA:cs-protocol} %{QS:cs-user-agent} %{DATA:cs-cookie} %{DATA:cs-referer}"
        }
    }
    date {
        match => ["timestamp", "YYYY-MM-dd HH:mm:ss"]
        target => "@timestamp"
    }
}

output {
    elasticsearch {
        hosts => ["localhost:9200"]
        index => "index-%{+YYYY.MM.dd}"
    }
    stdout {
        codec => rubydebug
    }
}

```

Patterns file:

```auto
CUSTOMIP (?:%{IP}|-)
CUSTOMURIPATH (?:%{URIPATH}|-)
CUSTOMPORT (?:%{POSINT}|-)

```

The problem is that if I remove the date filter, all the fields are processed but of course the timestamp that catches me is the moment of reading the file.

If I leave the date filter, it gives me a grok parse failure, which I do not understand because it parses well when date filter is gone.

---

<div class="post-metadata">

**Author:** ![raistlin2912](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raistlin2912/32/80178_2.png) [@raistlin2912](https://discuss.elastic.co/u/raistlin2912)\
**Post date:** [December 3, 2020, 1:46pm UTC](https://discuss.elastic.co/t/logstash-error-when-use-date-filter/257517/2 "2020-12-03T13:46:01Z")

</div>

Sorry, the problem is that some lines in logs not matches grok filter. The filter date is correct.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 31, 2020, 1:46pm UTC](https://discuss.elastic.co/t/logstash-error-when-use-date-filter/257517/3 "2020-12-31T13:46:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
