# Logstash: Not able to parse date field from csv

**URL:** <https://discuss.elastic.co/t/logstash-not-able-to-parse-date-field-from-csv/169994>\
**Category:** Logstash\
**Created:** [February 26, 2019, 11:44am UTC](https://discuss.elastic.co/t/logstash-not-able-to-parse-date-field-from-csv/169994 "2019-02-26T11:44:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rparmar812](https://avatars.discourse-cdn.com/v4/letter/r/e95f7d/32.png) [@rparmar812](https://discuss.elastic.co/u/rparmar812)\
**Post date:** [February 26, 2019, 11:44am UTC](https://discuss.elastic.co/t/logstash-not-able-to-parse-date-field-from-csv/169994/1 "2019-02-26T11:44:07Z")

</div>

I'm not able to parse date field ("Time") from given csv file. it's giving error all the time.  
Help will be appreciated.

**CSV**  
Time,TotalMsg,CancelMsg,NEWMsg,ModifyMsg,CancelThrottle,ModifyThrottle,NEWThrottle,TOTALThrottle,NewThrottlePercent,ModifyThrottlePercent,CancelThrottlePercent  
20190215-09:15,53867,3178,2724,47965,1258,5156,99,6513,3,10,39  
20190215-09:16,31272,1051,1156,29065,98,2267,0,2365,0,7,9  
20190215-09:17,21773,831,1044,19898,10,369,0,379,0,1,1

**Logstash config**  
input {

file {

path =\> "/home/ramesh/Final.Throttle.txt\*"

start\_position =\> "beginning"

sincedb\_path =\> "/dev/null"

}

}

filter {

csv {  
columns =\> [  
"Time",  
"TotalMsg",  
"CancelMsg",  
"NEWMsg",  
"ModifyMsg",  
"CancelThrottle",  
"ModifyThrottle",  
"NEWThrottle",  
"TOTALThrottle",  
"NewThrottlePercent",  
"ModifyThrottlePercent",  
"CancelThrottlePercent"  
]  
separator =\> ","  
remove\_field =\> ["message"]  
}  
date {  
match =\> ["Time","yyyyMMdd-HH:mm"]  
target =\> "Time"  
}

}

output {

elasticsearch {

hosts =\> ["localhost:9200"]  
index =\> "dataset"  
}

stdout {}

}

**Error**  
[2019-02-26T17:04:48,873][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"dataset", :\_type=\>"doc", :routing=\>nil}, #LogStash::Event:0x44b0d1f4], :response=\>{"index"=\>{"\_index"=\>"dataset", "\_type"=\>"doc", "\_id"=\>"c9aVKWkBr\_HsS0z9-aV-", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field [Time] of type [date]", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"Invalid format: "20190215-15:25" is malformed at "0215-15:25""}}}}}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 26, 2019, 1:11pm UTC](https://discuss.elastic.co/t/logstash-not-able-to-parse-date-field-from-csv/169994/2 "2019-02-26T13:11:42Z")

</div>

If the date filter was working then the Time field would no longer contain "20190215-15:25" when it got to elasticsearch. And that date filter would parse that field if it had that format. So there has to be something you are not telling us...

---

<div class="post-metadata">

**Author:** ![rparmar812](https://avatars.discourse-cdn.com/v4/letter/r/e95f7d/32.png) [@rparmar812](https://discuss.elastic.co/u/rparmar812)\
**Post date:** [February 27, 2019, 4:18am UTC](https://discuss.elastic.co/t/logstash-not-able-to-parse-date-field-from-csv/169994/3 "2019-02-27T04:18:22Z")

</div>

Nothing to hide here. You can tell me what to explore more to fix this issue and so i can dig into it.  
You can see below log for more details.

[2019-02-26T17:02:19,658][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
[2019-02-26T17:02:19,825][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}  
[2019-02-26T17:02:19,871][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>6}  
[2019-02-26T17:02:19,875][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[2019-02-26T17:02:19,900][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//localhost:9200](https://localhost:9200)"]}  
[2019-02-26T17:02:19,914][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>nil}  
[2019-02-26T17:02:19,930][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
[2019-02-26T17:02:20,153][INFO][logstash.pipeline] Pipeline started successfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x363ff72f run\>"}  
[2019-02-26T17:02:20,209][INFO][filewatch.observingtail] START, creating Discoverer, Watch with file and sincedb collections  
[2019-02-26T17:02:20,212][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>}  
[2019-02-26T17:02:20,481][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2019-02-26T17:02:21,199][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"dataset", :\_type=\>"doc", :routing=\>nil}, #LogStash::Event:0xaf89fc1], :response=\>{"index"=\>{"\_index"=\>"dataset", "\_type"=\>"doc", "\_id"=\>"P9aTKWkBr\_HsS0z9uaL8", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field [Time] of type [date]", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"Invalid format: "20190215-09:19" is malformed at "0215-09:19""}}}}}  
[2019-02-26T17:02:21,206][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"dataset", :\_type=\>"doc", :routing=\>nil}, #LogStash::Event:0x4e13d656], :response=\>{"index"=\>{"\_index"=\>"dataset", "\_type"=\>"doc", "\_id"=\>"ltaTKWkBr\_HsS0z9uqIO", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field [Time] of type [date]", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"Invalid format: "20190215-09:20" is malformed at "0215-09:20""}}}}}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2019, 4:18am UTC](https://discuss.elastic.co/t/logstash-not-able-to-parse-date-field-from-csv/169994/4 "2019-03-27T04:18:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
