# Logstash Error

**URL:** <https://discuss.elastic.co/t/logstash-error/303872>\
**Category:** Logstash\
**Created:** [May 3, 2022, 7:44pm UTC](https://discuss.elastic.co/t/logstash-error/303872 "2022-05-03T19:44:58Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 4, 2022, 3:07am UTC](https://discuss.elastic.co/t/logstash-error/303872/2 "2022-05-04T03:07:24Z")

</div>

`ERROR: Unknown command 'â€“f'` looks very similar to [this](https://discuss.elastic.co/t/unable-to-start-logstash-error-unknown-command-i-f/198783/4). Do you have –f instead of -f?

> [@Akhil2](#):
>
> ```auto
> mutate {
> add_field => { "DOB" => "%{BIRTHDATE}" }
> }
> 	
> #	Process the birthdate as DOB. Convert the birthdate into a date value. 
> date {
> match => ["DOB", "yyyyMMdd"]
> target => "DOB"
> }
> 
> # remove all fields we dont need anymore. 
> mutate { 
> remove_field => ["BIRTHDATE"]
> }	
> 
> ```

That will work, but I would suggest

```
date {
	match => ["BIRTHDATE", "yyyyMMdd"]
	target => "DOB"
	remove_field => ["BIRTHDATE"]
}

```

That will leave the [BIRTHDATE] field intact if a date filter is unable to parse it. So if someone sends you dodgy data you will be able to see what is wrong with it.

---

_[View the full topic](https://discuss.elastic.co/t/logstash-error/303872)._
