# Logstash -- inconsistent result with Date

**URL:** <https://discuss.elastic.co/t/logstash-inconsistent-result-with-date/175904>\
**Category:** Logstash\
**Created:** [April 8, 2019, 6:53pm UTC](https://discuss.elastic.co/t/logstash-inconsistent-result-with-date/175904 "2019-04-08T18:53:36Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nsearch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nsearch/32/30705_2.png) [@Nsearch](https://discuss.elastic.co/u/Nsearch)\
**Post date:** [April 8, 2019, 6:53pm UTC](https://discuss.elastic.co/t/logstash-inconsistent-result-with-date/175904/1 "2019-04-08T18:53:36Z")

</div>

- Version: 5.6.3
- Operating System: RedHat 7.4
- Sample Data: "2019-03-10 02:00:00" will not work.
- Steps to Reproduce:

create a file with the following value:

"2019-03-10 02:00:00"

Here is a Logstash config. file::

input {  
beats {  
port =\> "5046"  
}  
}

filter {  
csv {

columns =\> ["UsageEndDate"]  
separator =\> ","

}

date {  
match =\> ["UsageEndDate", "yyyy-MM-dd HH:mm:ss"]  
timezone =\> "America/New\_York"  
target =\> "newEndDate"  
}

}

output {  
stdout { codec =\> rubydebug }

}

==========================================  
After kick off logstash, I am keep gettting \_dateparsefailure:

{  
"[@timestamp](https://github.com/timestamp)" =\> 2019-04-08T18:08:49.064Z,  
"offset" =\> 23,  
"[@Version](https://github.com/Version)" =\> "1",  
"input\_type" =\> "log",  
"beat" =\> {  
"name" =\> "kibana",  
"hostname" =\> "kibana",  
"version" =\> "5.6.3"  
},  
"host" =\> "kibana",  
"UsageEndDate" =\> "2019-03-10 02:00:00",  
"source" =\> "/mypath/aws-nc2.test",  
"message" =\> ""2019-03-10 02:00:00"",  
"type" =\> "log",  
"fields" =\> {  
"index" =\> "testing\_aws"  
},  
"tags" =\> [  
[0] "beats\_input\_codec\_plain\_applied",  
[1] "\_dateparsefailure"  
]  
}

I had no issue if the data is 2019-03-10 01:00:00

or any other hours, but only had issue with 02:00:00.

Thanks,

Noah

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 8, 2019, 7:17pm UTC](https://discuss.elastic.co/t/logstash-inconsistent-result-with-date/175904/2 "2019-04-08T19:17:39Z")

</div>

Daylight savings started on 3/10. There was no 2 AM. We went straight from 01:59:59 to 03:00:00.

---

<div class="post-metadata">

**Author:** ![Nsearch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nsearch/32/30705_2.png) [@Nsearch](https://discuss.elastic.co/u/Nsearch)\
**Post date:** [April 8, 2019, 7:20pm UTC](https://discuss.elastic.co/t/logstash-inconsistent-result-with-date/175904/3 "2019-04-08T19:20:46Z")

</div>

Thanks so much for quick reply. Any recommendation, other than looking for all my data and change them from 2 to 3?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 8, 2019, 7:30pm UTC](https://discuss.elastic.co/t/logstash-inconsistent-result-with-date/175904/4 "2019-04-08T19:30:34Z")

</div>

That's what I did when I was looking at [NYPD arrest data](https://data.cityofnewyork.us/Public-Safety/NYPD-Arrests-Data-Historic-/8h9b-rp9u), which had this issue. I had a function that would look for the start of EDT in each year and fix any affected timestamps.

---

<div class="post-metadata">

**Author:** ![Nsearch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nsearch/32/30705_2.png) [@Nsearch](https://discuss.elastic.co/u/Nsearch)\
**Post date:** [April 8, 2019, 7:30pm UTC](https://discuss.elastic.co/t/logstash-inconsistent-result-with-date/175904/5 "2019-04-08T19:30:45Z")

</div>

Ok, thanks. I just fixed issue by changing the timezone from timezone =\>"America/New\_York" to timezone='EST'

Not sure why it solved that if both were the same.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 8, 2019, 7:35pm UTC](https://discuss.elastic.co/t/logstash-inconsistent-result-with-date/175904/6 "2019-04-08T19:35:16Z")

</div>

EST and EDT are two different timezones. EST is 5 hours behind GMT. EDT is 4 hours behind. America/New\_York uses EDT from March to November.

---

<div class="post-metadata">

**Author:** ![Nsearch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nsearch/32/30705_2.png) [@Nsearch](https://discuss.elastic.co/u/Nsearch)\
**Post date:** [April 8, 2019, 7:59pm UTC](https://discuss.elastic.co/t/logstash-inconsistent-result-with-date/175904/7 "2019-04-08T19:59:29Z")

</div>

ok, so I am working with AWS billing file. I went to confirm what timezone they were using for the data. Found out it was UTC. I fixed the issue by, using timezone=\> "UTC".

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 6, 2019, 7:59pm UTC](https://discuss.elastic.co/t/logstash-inconsistent-result-with-date/175904/8 "2019-05-06T19:59:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
