# Logstash, parsing a localised date with HTTPDATE

**URL:** <https://discuss.elastic.co/t/logstash-parsing-a-localised-date-with-httpdate/330297>\
**Category:** Logstash\
**Created:** [April 19, 2023, 11:28am UTC](https://discuss.elastic.co/t/logstash-parsing-a-localised-date-with-httpdate/330297 "2023-04-19T11:28:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![GreenEyed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/greeneyed/32/70123_2.png) [@GreenEyed](https://discuss.elastic.co/u/GreenEyed)\
**Post date:** [April 19, 2023, 11:28am UTC](https://discuss.elastic.co/t/logstash-parsing-a-localised-date-with-httpdate/330297/1 "2023-04-19T11:28:08Z")

</div>

Hi there,  
We have a library that is sending access logs to logstash with a "similar" to Apache format. We have created the regexp in grok to parse it but I have detected that the library is using the default format, localised depending on the OS default locale... and it is not configurable (yep, planning to open an issue against the library as well).  
With that, the problem is the month name, given that the regexp fails to parse month names in a different locale. Is there some way to get logstash to parse that by specifying the locale that is has to be used to parse the date?

For example, this is the part of the pipeline that fails:

```auto
     grok {
       match => { 'message' => '%{IPORHOST:client_ip} - %{DATA:userid} \[%{HTTPDATE:request.timestamp}\] "%{WORD:request.method} %{URIPATHPARAM:request.resource} HTTP/%{NUMBER:request.version}" %{NUMBER:response.status_code} %{NUMBER:response.size} %{NUMBER:service_time} "%{DATA:referer}" "%{DATA:user_agent}"' }
       remove_field => ["message"]
     }

```

And a sample line that the library produces is (Notice abr from Abril in Spanish):  
`x.x.x.x - - [19/abr/2023:10:43:19 +0000] "GET /whatever HTTP/1.1" 200 15 1 "-" "Agent"`  
whereas this one can be parsed (In this case, apr from April):  
`x.x.x.x - - [19/apr/2023:10:43:19 +0000] "GET /whatever HTTP/1.1" 200 15 1 "-" "Agent"`

Thank you!

PD: If someone wants to pay a visit to whomever decided using a localizable format was a good idea for a default standard format (NCSA Common log format), I have a pitch and fork that I'd like to bring along 😃 .

---

<div class="post-metadata">

**Author:** ![GreenEyed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/greeneyed/32/70123_2.png) [@GreenEyed](https://discuss.elastic.co/u/GreenEyed)\
**Post date:** [April 19, 2023, 11:54am UTC](https://discuss.elastic.co/t/logstash-parsing-a-localised-date-with-httpdate/330297/2 "2023-04-19T11:54:11Z")

</div>

Digging in the library, I found a workaround to configure the locale, but it would still be nice to know how to do that in logstash, just in case.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 19, 2023, 3:31pm UTC](https://discuss.elastic.co/t/logstash-parsing-a-localised-date-with-httpdate/330297/3 "2023-04-19T15:31:49Z")

</div>

> [@GreenEyed](#):
>
> Is there some way to get logstash to parse that by specifying the locale that is has to be used to parse the date?

Not for grok. HTTPDATE references MONTH, and [MONTH](https://github.com/logstash-plugins/logstash-patterns-core/blob/f01f3f34cfab13a28b0822bdba33db41823cb1d8/patterns/legacy/grok-patterns#L51) is strictly English.

Once you have parsed the field out of the line the date filter has a locale option you can set.

---

<div class="post-metadata">

**Author:** ![GreenEyed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/greeneyed/32/70123_2.png) [@GreenEyed](https://discuss.elastic.co/u/GreenEyed)\
**Post date:** [April 19, 2023, 6:15pm UTC](https://discuss.elastic.co/t/logstash-parsing-a-localised-date-with-httpdate/330297/4 "2023-04-19T18:15:06Z")

</div>

Aha, so the idea would be to just extract the field as a string and then after the grok, parse that "string field" with a date filter with the right locale and get the proper request.timestamp field.  
Neat. I was maybe asking too much from the grok filter as allowing such things specified there might make it, even more, complex.

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 17, 2023, 6:15pm UTC](https://discuss.elastic.co/t/logstash-parsing-a-localised-date-with-httpdate/330297/5 "2023-05-17T18:15:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
