# Logstash find a date/time in a log entry

**URL:** https://discuss.elastic.co/t/logstash-find-a-date-time-in-a-log-entry/184995
**Category:** Logstash
**Created:** [June 10, 2019, 1:18pm UTC](https://discuss.elastic.co/t/logstash-find-a-date-time-in-a-log-entry/184995 "2019-06-10T13:18:38Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![paiz1556](https://avatars.discourse-cdn.com/v4/letter/p/a88e57/32.png) [@paiz1556](https://discuss.elastic.co/u/paiz1556)
#### Post date: [June 10, 2019, 1:18pm UTC](https://discuss.elastic.co/t/logstash-find-a-date-time-in-a-log-entry/184995/1 "2019-06-10T13:18:39Z")

</div>

I've just started using logstash and I'm working on trying to parse a log and push it into solr using the solr\_http plugin.

I successfully used a grok filter to pull the severity out as a separate field, but I can't seem to get the date to parse.

My expectation would be the date would be added to a field called mydate similar to severity.

Sample file record:

```
localhost-startStop-1 2019-06-08 05:08:21,497 DEBUG lking.spi.MetamodelGraphWalker Visiting attribute path : tableRating

```

Here is my config:

```
#Try to push data into solr

input {
        file {
			 path => "//serverpath/hibernate.log"
                             start_position => "beginning"
         }
    }
filter {
	  grok {
		match => { "message" => "%{LOGLEVEL:severity}"}
	  }
	  date {
		match => ["mydate", "yyyy-MM-dd HH:mm:ss,SSS"]
		target => "mydate"
	  }
	  
	}		
output {
            solr_http {
                    solr_url => "http://localhost:8080/solr/logStuff"
                    }        
	}

```

The result of this is that data gets pushed into solr, there is a separate field for 'severity'. But nothing for mydate. I have the log level turned on to TRACE and nothing seems to come out on concerning the mydate field

---

<div class="post-metadata">

### Author: ![paiz1556](https://avatars.discourse-cdn.com/v4/letter/p/a88e57/32.png) [@paiz1556](https://discuss.elastic.co/u/paiz1556)
#### Post date: [June 10, 2019, 2:41pm UTC](https://discuss.elastic.co/t/logstash-find-a-date-time-in-a-log-entry/184995/2 "2019-06-10T14:41:28Z")

</div>

Interesting. I got his to work, but not how I expected. I added a second "grok" filter for the date.

I am still curious why the date filter didn't work though. Any insight is welcome.

Working filter:  
#Try to push data into solr

```
input {
    file {
			 path => "//serverpath/hibernate.log"
                             start_position => "beginning"
         }
    }
filter {
	  grok {
		match => { "message" => "%{LOGLEVEL:severity}"}
	  }
	  
	  grok {
		match => { "message" => "%{TIMESTAMP_ISO8601:logdate}"}
	  }
	  
	}		
output {
            solr_http {
                    solr_url => "http://localhost:8080/solr/logStuff"
                    }        
	}
```

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [June 10, 2019, 5:30pm UTC](https://discuss.elastic.co/t/logstash-find-a-date-time-in-a-log-entry/184995/3 "2019-06-10T17:30:33Z")

</div>

> [@paiz1556](#):
>
> I am still curious why the date filter didn't work though. Any insight is welcome.

Nothing in your first configuration creates a field called mydate, so the date filter is a no-op.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 8, 2019, 5:30pm UTC](https://discuss.elastic.co/t/logstash-find-a-date-time-in-a-log-entry/184995/4 "2019-07-08T17:30:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
