# Logstash timestamp format

**URL:** <https://discuss.elastic.co/t/logstash-timestamp-format/359949>\
**Category:** Logstash\
**Created:** [May 22, 2024, 3:02am UTC](https://discuss.elastic.co/t/logstash-timestamp-format/359949 "2024-05-22T03:02:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![iceman0410](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iceman0410/32/134395_2.png) [@iceman0410](https://discuss.elastic.co/u/iceman0410)\
**Post date:** [May 22, 2024, 3:02am UTC](https://discuss.elastic.co/t/logstash-timestamp-format/359949/1 "2024-05-22T03:02:47Z")

</div>

Hi everyone,

I have a log message as below. The date is not match any format so logstash does not parse timestamp. Anyone please help me review my logstash conf and advice please. Thanks

Log Message:  
[30@00:01:33.048:] ===\> INFO: Next log is "/app/svacc\_pr\_ctm\_em/ctm\_em/log/cmsg\_log.CMSGATE.20220330.0", time \>00:01:33.048:\<

My Logstash config:

input {  
beats {  
port =\> 5044  
}  
}  
filter  
{  
grok {  
match =\> { "message" =\> "[%{DATA:dts}:]%{SPACE}===\>%{SPACE}%{LOGLEVEL:lvl}%{GREEDYDATA:rest}" }  
}  
date {  
match =\> ["dts", "hh.mm.ss.SSS"]  
target =\> "@timestamp"  
timezone =\> "UTC"  
}  
}  
output {  
stdout {  
codec =\> rubydebug

 ![adsasd](https://us1.discourse-cdn.com/elastic/original/3X/0/0/007d64997a83c594bc5db2389d6ec2cad6eb2118.png)

}  
}

The out as picture above

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [May 22, 2024, 2:55pm UTC](https://discuss.elastic.co/t/logstash-timestamp-format/359949/2 "2024-05-22T14:55:30Z")

</div>

Hi,

The format you've specified in the date filter, "hh.mm.ss.SSS", does not match the format of the timestamp in your log message.

Regards

---

<div class="post-metadata">

**Author:** ![iceman0410](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iceman0410/32/134395_2.png) [@iceman0410](https://discuss.elastic.co/u/iceman0410)\
**Post date:** [May 23, 2024, 1:21am UTC](https://discuss.elastic.co/t/logstash-timestamp-format/359949/3 "2024-05-23T01:21:51Z")

</div>

Hi @yago82 ,

I tried date format below but it does not work. Can you give advice?

filter  
{  
grok {  
match =\> { "message" =\> "[(?%{MONTHDAY:day}%{DATA:unknown}%{TIME}:)]%{SPACE}%{URIQUERY}%{SPACE}%{LOGLEVEL:lvl}%{GREEDYDATA:rest}" }  
}  
date {  
match =\> ["dts", "ddHH:mm:ss.SSS"]  
remove\_field =\> ["unknown"]  
target =\> "@timestamp"  
timezone =\> "UTC"  
}

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 23, 2024, 3:52am UTC](https://discuss.elastic.co/t/logstash-timestamp-format/359949/4 "2024-05-23T03:52:44Z")

</div>

The value of your date field `dts` is something like `30@00:01:33.048:`, none of the date patterns you shared will match this.

You need to build a pattern that will match this string, but you need to provide more context about how this is created.

Is the `30@` part constant or it can change? If this is constant the `30@` part needs to be in your date pattern.

The following filter would parse it:

```auto
    date {
        match => ["message", "'30@'HH:mm:ss.SSS"]
    }

```

Keep in mind that your date string does not have any date information, so if you use the `date` filter in this case all your dates will be in `2024-01-01` as the example below:

```auto
{
       "dts" => "30@00:01:33.048",
      "@version" => "1",
    "@timestamp" => 2024-01-01T03:01:33.048Z,
}

```

---

<div class="post-metadata">

**Author:** ![iceman0410](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iceman0410/32/134395_2.png) [@iceman0410](https://discuss.elastic.co/u/iceman0410)\
**Post date:** [May 23, 2024, 5:32am UTC](https://discuss.elastic.co/t/logstash-timestamp-format/359949/5 "2024-05-23T05:32:12Z")

</div>

Thanks @leandrojmp , it works. I have another log message with multiple lines. I would like to merge all to one line message. Could you please look at my Grok and advice

Log: "[timestamp: 1621431760] abort handler of pid 1823 thread 1848977280  
\*\*\* Stacks of threads \*\*\* (current thread is 1848977280)  
Stack of thread=1848977280, depth=3  
main  
shutdownServices  
EMThriftServer::stop"

My Grok: [%{DATA}:%{SPACE}%{NUMBER:dts}]%{SPACE}%{GREEDYDATA:rest}
