# Logstash tcp plugin

**URL:** <https://discuss.elastic.co/t/logstash-tcp-plugin/319584>\
**Category:** Logstash\
**Created:** [November 22, 2022, 8:21pm UTC](https://discuss.elastic.co/t/logstash-tcp-plugin/319584 "2022-11-22T20:21:32Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![SilasMuniz1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/silasmuniz1/32/108267_2.png) [@SilasMuniz1](https://discuss.elastic.co/u/SilasMuniz1)\
**Post date:** [November 22, 2022, 8:21pm UTC](https://discuss.elastic.co/t/logstash-tcp-plugin/319584/1 "2022-11-22T20:21:32Z")

</div>

Hello,

I need convert a data field to date field. I am working in restore processed, where I get an old file and insert into elasticsearch by logstash.

I received a file with this date format [06/Jun/2022:13:20:01 -0300]. I've tried use many grok patern(SYSLOGTIMESTAMP, TIMESTAMP\_ISO8601, DATESTAMP\_EVENTLOG) any one work, only data or greedydata.

I parsed this information with this grok: [%{DATA:Data\_Evento} -0300], I keep only date and hour. I didn't use -0300.

But I need to convert to date, because I use this information to make search.

I tried use date inside grok.

\< date {  
match =\> ["Data\_Evento", Date]  
target =\> "Data\_Evento" /\>

But it didn't work.

Is there any grok timestamp format to resolved it ? Or I will need to make a patter\_custom to resolve it ?

Regards,

Silas Muniz

---

<div class="post-metadata">

**Author:** ![dmrlixos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dmrlixos/32/99836_2.png) [@dmrlixos](https://discuss.elastic.co/u/dmrlixos)\
**Post date:** [November 23, 2022, 12:37am UTC](https://discuss.elastic.co/t/logstash-tcp-plugin/319584/2 "2022-11-23T00:37:45Z")

</div>

Hi Silas

Did you try use mapping template, and put the field data\_evento as date on mapping ?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 23, 2022, 2:40am UTC](https://discuss.elastic.co/t/logstash-tcp-plugin/319584/3 "2022-11-23T02:40:55Z")

</div>

What does your message looks like? Can you share an example?

If you have the field `Data_evento` with this `06/Jun/2022:13:20:01` value, you can use the following date filter to parse it.

```auto
  date {
    match => ["Data_evento", "dd/MMM/yyyy:HH:mm:ss"]
    timezone => "-0300"
  }

```

Since you removed the timezone information from the date string, you need to configure the `timezone` option in the `date` filter since your date has an offset.

---

<div class="post-metadata">

**Author:** ![SilasMuniz1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/silasmuniz1/32/108267_2.png) [@SilasMuniz1](https://discuss.elastic.co/u/SilasMuniz1)\
**Post date:** [November 24, 2022, 12:08am UTC](https://discuss.elastic.co/t/logstash-tcp-plugin/319584/4 "2022-11-24T00:08:35Z")

</div>

@leandrojmp @dmrlixos

I've resolved my problem using date format inside index template.  
I configured this date format: dd/MMM/yyyy:HH:mm:ss. Afther that I sent data from logstash.

Thank you !!!

Silas Muniz

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 22, 2022, 12:09am UTC](https://discuss.elastic.co/t/logstash-tcp-plugin/319584/5 "2022-12-22T00:09:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
