# LogStash filter for matching timestamp example: \[2024-01-04 23:00:00,931\]

**URL:** <https://discuss.elastic.co/t/logstash-filter-for-matching-timestamp-example-2024-01-04-2300-931/350549>\
**Category:** Logstash\
**Created:** [January 8, 2024, 7:35am UTC](https://discuss.elastic.co/t/logstash-filter-for-matching-timestamp-example-2024-01-04-2300-931/350549 "2024-01-08T07:35:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![criss79](https://avatars.discourse-cdn.com/v4/letter/c/df788c/32.png) [@criss79](https://discuss.elastic.co/u/criss79)\
**Post date:** [January 8, 2024, 7:35am UTC](https://discuss.elastic.co/t/logstash-filter-for-matching-timestamp-example-2024-01-04-2300-931/350549/1 "2024-01-08T07:35:14Z")

</div>

Hi guys,  
I am having difficulties to match this timestamp format for a log entry that looks like this:  
[timestamp] [Loglevel] message  
Log entry example:  
[2024-01-04 23:00:00,931] [INFO] Multi\_Language.UserInfoContainer PushNotificationChannels.SpreadsUpdated with .DistributedCache.Common.PublisherInfoExtened

My Logstash filter:

```auto
filter {
    grok {
    match => { "message" => "^\[(?<timestamp>%{DAY} %{MONTH} %{MONTHDAY} %{TIME} %{YEAR})\]\s+(\[%{WORD:loglevel}\]\s+)?%{GREEDYDATA:message}" }
    overwrite => ["message"]
    }
  kv {
    field_split => " "
}
  mutate {
    remove_field => ["event","log","input","ecs","version","name","@version","input","type","agent","offset","tags"]
    lowercase => ["[host][name]" ]
}
}

```

For the following log entry example the filter above works but this will not help me as I need the timestamp in this format “[2024-01-04 23:00:00,931]”.

[Thu Nov 01 21:56:35 2012] [INFO] Multi\_Language.UserInfoContainer PushNotificationChannels.SpreadsUpdated with .DistributedCache.Common.PublisherInfoExtened

I appreciate any ideas.

Have a nice day all.

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [January 8, 2024, 8:40am UTC](https://discuss.elastic.co/t/logstash-filter-for-matching-timestamp-example-2024-01-04-2300-931/350549/2 "2024-01-08T08:40:56Z")

</div>

Hi,

The grok pattern you're using is for a different timestamp format.

Here's a modified version of your Logstash filter that should work with your timestamp format:

```auto
filter {
  grok {
    match => { "message" => "^\[(?<timestamp>%{YEAR}-%{MONTHNUM}-%{MONTHDAY} %{TIME})\]\s+\[%{LOGLEVEL:loglevel}\]\s+%{GREEDYDATA:message}" }
    overwrite => ["message"]
  }
  date {
    match => ["timestamp", "YYYY-MM-dd HH:mm:ss,SSS"]
    target => "@timestamp"
    remove_field => ["timestamp"]
  }

```

Regards

---

<div class="post-metadata">

**Author:** ![criss79](https://avatars.discourse-cdn.com/v4/letter/c/df788c/32.png) [@criss79](https://discuss.elastic.co/u/criss79)\
**Post date:** [January 8, 2024, 10:07am UTC](https://discuss.elastic.co/t/logstash-filter-for-matching-timestamp-example-2024-01-04-2300-931/350549/3 "2024-01-08T10:07:02Z")

</div>

Thank you yago82,

Your filter seems to be correct, no errors, however there are no entries in elastic db. I searched all indexes and data streams.

I found the following filter and is handling my timestamp correctly. I also changed the separators since my logs contains characters like [] { }.

```auto
filter {
  dissect {
    mapping => {
        "message" => "|%{time}| |%{level}| |%{logmsg}|"
      }
}
  kv {
    field_split => " "
}
  mutate {
    remove_field => ["event","log","input","ecs","version","name","@version","input","type","agent","offset","tags"]
    lowercase => ["[host][name]" ]
}
}

```

Thanks again.  
Criss.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 5, 2024, 10:07am UTC](https://discuss.elastic.co/t/logstash-filter-for-matching-timestamp-example-2024-01-04-2300-931/350549/4 "2024-02-05T10:07:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
