# Logstash time filter not working

**URL:** <https://discuss.elastic.co/t/logstash-time-filter-not-working/115068>\
**Category:** Logstash\
**Created:** [January 11, 2018, 11:13am UTC](https://discuss.elastic.co/t/logstash-time-filter-not-working/115068 "2018-01-11T11:13:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rijinmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rijinmp/32/24634_2.png) [@rijinmp](https://discuss.elastic.co/u/rijinmp)\
**Post date:** [January 11, 2018, 11:13am UTC](https://discuss.elastic.co/t/logstash-time-filter-not-working/115068/1 "2018-01-11T11:13:56Z")

</div>

## My CSV

[xyz.com](http://xyz.com),1/1/2018 12:17:37 PM,62  
[xyz.com](http://xyz.com),7/15/2017 1:11:34 AM,62  
[xyz.com](http://xyz.com),7/15/2017 1:06:34 AM,62  
[xyz.com](http://xyz.com),7/15/2017 1:01:34 AM,78

## Filter

filter {

csv {  
separator =\> ","  
columns =\> [  
"URL",  
"Date",  
"Response"  
]  
}  
date {  
match =\> ["Date","M/d/yyyy H:mm:ss"]  
target =\> "@timestamp"  
}

}

## Outpu

"Response" =\> "62",  
"path" =\> "/home/elastic/elk/samplelog/urlresponse.csv",  
"@timestamp" =\> 2018-01-11T10:45:21.323Z,  
"@version" =\> "1",  
"host" =\> "localhost.localdomain",  
"message" =\> "[xyz.com](http://xyz.com),1/1/2018 12:17:37 PM,62\r",  
"URL" =\> "[xyz.com](http://xyz.com)",  
"Date" =\> "1/1/2018 12:17:37 PM",  
"tags" =\> [  
[0] "\_dateparsefailure"

CSV time id not filtering for @timestamp

i want to use CSV time ( "Date" =\> "1/1/2018 12:17:37 PM",) for indexing @timestamp.

---

<div class="post-metadata">

**Author:** ![paz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paz/32/28003_2.png) [@paz](https://discuss.elastic.co/u/paz)\
**Post date:** [January 11, 2018, 2:53pm UTC](https://discuss.elastic.co/t/logstash-time-filter-not-working/115068/2 "2018-01-11T14:53:52Z")

</div>

Your date filter pattern is wrong, it's missing the AM/PM capture flag.

Also you might want to set a timezone on the date filter as well, else it will get your system's timezone and convert to UTC (so unless your system is also on UTC you could have offsets applied in your timestamp).

Try this:

```auto
filter {
    csv {
        separator => ","
        columns => ["URL","Date","Response"]
    }
    date {
        match => ["Date","M/d/yyyy H:mm:ss a"]
        timezone => "Etc/UTC"
        target => "@timestamp"
    }
}
```

---

<div class="post-metadata">

**Author:** ![rijinmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rijinmp/32/24634_2.png) [@rijinmp](https://discuss.elastic.co/u/rijinmp)\
**Post date:** [January 16, 2018, 6:41am UTC](https://discuss.elastic.co/t/logstash-time-filter-not-working/115068/3 "2018-01-16T06:41:55Z")

</div>

Thank you @paz

🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 13, 2018, 6:41am UTC](https://discuss.elastic.co/t/logstash-time-filter-not-working/115068/4 "2018-02-13T06:41:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
