# Logstash time parsing error

**URL:** <https://discuss.elastic.co/t/logstash-time-parsing-error/52765>\
**Category:** Logstash\
**Created:** [June 14, 2016, 5:27pm UTC](https://discuss.elastic.co/t/logstash-time-parsing-error/52765 "2016-06-14T17:27:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kennedy\_Kan1](https://avatars.discourse-cdn.com/v4/letter/k/cc9497/32.png) [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)\
**Post date:** [June 14, 2016, 5:27pm UTC](https://discuss.elastic.co/t/logstash-time-parsing-error/52765/1 "2016-06-14T17:27:00Z")

</div>

I have come across with logstash date parsing error like the follow.

> ←[33mFailed parsing date from field {:field=\>"Date", :value=\>"Sep 19, 2015 10:16:36 PM HKT", :exception=\>"Invalid format  
> : "Sep 19, 2015 10:16:36 PM HKT" is malformed at " 19, 2015 10:16:36 PM HKT"", :config\_parsers=\>"MMM dd, yyyy HH:mm:  
> ss aa Z,MMM d, yyyy HH:mm:ss aa Z", :config\_locale=\>"default=en\_US", :level=\>:warn}←[0m

How can I solve that?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 14, 2016, 5:54pm UTC](https://discuss.elastic.co/t/logstash-time-parsing-error/52765/2 "2016-06-14T17:54:02Z")

</div>

I can't reproduce that error:

```nohighlight
$ cat test.config
input { stdin { } }
output { stdout { codec => rubydebug } }
filter {
  date {
    match => ["message", "MMM dd, yyyy HH:mm:ss aa Z"]
  }
}
$ echo 'Sep 19, 2015 10:16:36 PM HKT' | /opt/logstash/bin/logstash -f test.config
Settings: Default pipeline workers: 2
Pipeline main started
Failed parsing date from field {:field=>"message", :value=>"Sep 19, 2015 10:16:36 PM HKT", :exception=>"Invalid format: \"Sep 19, 2015 10:16:36 PM HKT\" is malformed at \"HKT\"", :config_parsers=>"MMM dd, yyyy HH:mm:ss aa Z", :config_locale=>"default=en_US", :level=>:warn}
{
       "message" => "Sep 19, 2015 10:16:36 PM HKT",
      "@version" => "1",
    "@timestamp" => "2016-06-14T17:52:46.594Z",
          "host" => "hallonet",
          "tags" => [
        [0] "_dateparsefailure"
    ]
}
Pipeline main has been shutdown
stopping pipeline {:id=>"main"}

```

However, as this example shows the date filter—as documented—isn't capable of parsing timezone names.

---

<div class="post-metadata">

**Author:** ![Kennedy\_Kan1](https://avatars.discourse-cdn.com/v4/letter/k/cc9497/32.png) [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)\
**Post date:** [June 15, 2016, 5:11am UTC](https://discuss.elastic.co/t/logstash-time-parsing-error/52765/3 "2016-06-15T05:11:18Z")

</div>

Thanks for your information.  
I have made a workaround in just collecting the `Sep 19, 2015 10:16:36 PM` without timezone and successfully parse as @timestamp. But yet another problem is that it automatically turns my timestamp from +8 to +0 as shown below.

```
           "@timestamp" => "2015-09-19T02:16:52.000Z",
                 "Date" => "Sep 19, 2015 10:16:52 PM ",

```

How can I configure it to use localtime or how to configure kibana to turn back the timestamp to localtime for analytics?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 15, 2016, 5:43am UTC](https://discuss.elastic.co/t/logstash-time-parsing-error/52765/4 "2016-06-15T05:43:03Z")

</div>

The `@timestamp` field is always UTC. Kibana will by default convert it back to the browser's timezone.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:52am UTC](https://discuss.elastic.co/t/logstash-time-parsing-error/52765/5 "2017-07-06T04:52:52Z")

</div>


