# Logstash Replace timestamp from csv

**URL:** <https://discuss.elastic.co/t/logstash-replace-timestamp-from-csv/141188>\
**Category:** Logstash\
**Created:** [July 23, 2018, 1:57pm UTC](https://discuss.elastic.co/t/logstash-replace-timestamp-from-csv/141188 "2018-07-23T13:57:40Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![logesh\_j](https://avatars.discourse-cdn.com/v4/letter/l/ecccb3/32.png) [@logesh\_j](https://discuss.elastic.co/u/logesh_j)\
**Post date:** [July 23, 2018, 1:57pm UTC](https://discuss.elastic.co/t/logstash-replace-timestamp-from-csv/141188/1 "2018-07-23T13:57:40Z")

</div>

I am try to replace the timestamp with the field from log file. But it is not getting updated. Getting Date parse error \_dateparsefailure and still not getting updated. Attached the config file for reference.

Date in the Log file format is :6/19/2018 9:42:00 PM

input {  
file {  
path =\> "D:/IntraDay1.csv"  
start\_position =\> beginning  
# to read from the beginning of file  
sincedb\_path =\> "/dev/null"  
}  
}

filter {

```
csv {
   columns => ["Dispo"]

}

```

mutate {

```
	convert => { 
		" 
										
	}

```

}

date {  
match =\> ["DateTime", "yyyy-MM-dd HH:mm:ss,SSS"]  
timezone =\> "UTC"  
add\_field =\> { "Status" =\> "Matched"} # add\_tag =\> ["timestamp\_matched"]

}

}

output {

elasticsearch {

action =\> "index"  
hosts =\> "localhost:9200"  
index =\> "intraday"  
workers =\> 1

}  
stdout { codec =\> rubydebug }

}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 23, 2018, 2:43pm UTC](https://discuss.elastic.co/t/logstash-replace-timestamp-from-csv/141188/2 "2018-07-23T14:43:36Z")

</div>

> [@logesh\_j](#):
>
> 6/19/2018 9:42:00 PM

And you are trying to parse that using

```
match => ["DateTime", "yyyy-MM-dd HH:mm:ss,SSS"]

```

Try

```
 date { match => ["DateTime", "M/dd/yyyy h:mm:ss aa"] }

```

---

<div class="post-metadata">

**Author:** ![logesh\_j](https://avatars.discourse-cdn.com/v4/letter/l/ecccb3/32.png) [@logesh\_j](https://discuss.elastic.co/u/logesh_j)\
**Post date:** [July 23, 2018, 2:51pm UTC](https://discuss.elastic.co/t/logstash-replace-timestamp-from-csv/141188/3 "2018-07-23T14:51:16Z")

</div>

> [@Badger](#):
>
> date { match =\> ["DateTime", "M/dd/yyyy h:mm:ss aa"] }

Thanks Badger still the same dateparse error and timestamp is not getting updated.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 23, 2018, 2:52pm UTC](https://discuss.elastic.co/t/logstash-replace-timestamp-from-csv/141188/4 "2018-07-23T14:52:29Z")

</div>

Show us the message from the JSON tab in Kibana Discover

---

<div class="post-metadata">

**Author:** ![logesh\_j](https://avatars.discourse-cdn.com/v4/letter/l/ecccb3/32.png) [@logesh\_j](https://discuss.elastic.co/u/logesh_j)\
**Post date:** [July 23, 2018, 4:04pm UTC](https://discuss.elastic.co/t/logstash-replace-timestamp-from-csv/141188/5 "2018-07-23T16:04:24Z")

</div>

```
indent preformatted text by 4 spaces

```

modified the naming convention just for security

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 23, 2018, 4:07pm UTC](https://discuss.elastic.co/t/logstash-replace-timestamp-from-csv/141188/6 "2018-07-23T16:07:23Z")

</div>

> [@logesh\_j](#):
>
> "DateTime": "6/10/18 10:57 AM"

```
date { match => ["DateTime", "M/dd/yy h:mm aa"] }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 20, 2018, 4:07pm UTC](https://discuss.elastic.co/t/logstash-replace-timestamp-from-csv/141188/7 "2018-08-20T16:07:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
