# Logstash setting field to date without any options set

**URL:** <https://discuss.elastic.co/t/logstash-setting-field-to-date-without-any-options-set/270621>\
**Category:** Logstash\
**Created:** [April 19, 2021, 7:50pm UTC](https://discuss.elastic.co/t/logstash-setting-field-to-date-without-any-options-set/270621 "2021-04-19T19:50:12Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [April 19, 2021, 7:50pm UTC](https://discuss.elastic.co/t/logstash-setting-field-to-date-without-any-options-set/270621/1 "2021-04-19T19:50:12Z")

</div>

I am ingesting a csv file.

The only options set in the filter are a gsub meant to remove double quotes; a csv filter which skips the header, the separator and the column/field names set; and a mutate to add one field and remove the message.

The field is not being converted in any way nor is it being used in the ID so i am not sure as to why it i keep getting a failed to parse date field [-] with format [yyyy/MM/dd HH:mm:sse\_exception", "reason"=\>"Failed to parse with all enclosed parsers error.

Or how can I make it so it doesnt force the date field. I've tried the convert field to string option but I still get the same error.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 19, 2021, 9:07pm UTC](https://discuss.elastic.co/t/logstash-setting-field-to-date-without-any-options-set/270621/2 "2021-04-19T21:07:09Z")

</div>

What exactly is the error message?

---

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [April 19, 2021, 9:42pm UTC](https://discuss.elastic.co/t/logstash-setting-field-to-date-without-any-options-set/270621/3 "2021-04-19T21:42:50Z")

</div>

Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>"", :\_index=\>"", :\_type=\>"\_doc", :routing=\>nil}, #LogStash::Event:], :response=\>{"index"=\>{"\_index"=\>"", "\_type"=\>"\_doc", "\_id"=\>"", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field of type [date] in document with id ''", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"failed to parse date field [-] with format [yyyy/MM/dd HH:mm:ss||yyyy/MM/dd||epoch\_millis]", "caused\_by"=\>{"type"=\>"date\_time\_parse\_exception", "reason"=\>"Failed to parse with all enclosed parsers"

I removed the id and field names but this is the overall error. I understood that some of the records for this field have a value of "-" and because of this the error is saying it cant parse that value into the date type listed in the error. However, I assume logstash just recognized the field as that of date type because i didnt explicitly set it. Any way to not force it to set a field to that of date?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 19, 2021, 10:17pm UTC](https://discuss.elastic.co/t/logstash-setting-field-to-date-without-any-options-set/270621/4 "2021-04-19T22:17:56Z")

</div>

Once elasticsearch decides a field is a date then a document where that field is not a date cannot be indexed. [dynamic mapping](https://www.elastic.co/guide/en/elasticsearch/reference/current/dynamic-field-mapping.html) controls how it decides the type of a field.

If you do not want the field to be a date then it is probably best to use a template to tell elasticsearch that.

If you want the field to be a date in elasticsearch and index that document anyway you will need to remove the field

```
if [fieldName] == "-" { mutate { remove_field => ["fieldName"] } }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 17, 2021, 10:17pm UTC](https://discuss.elastic.co/t/logstash-setting-field-to-date-without-any-options-set/270621/5 "2021-05-17T22:17:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
