# Logstash Timstamp:\_dateparsefailure issue

**URL:** https://discuss.elastic.co/t/logstash-timstamp-dateparsefailure-issue/127314
**Category:** Logstash
**Created:** [April 9, 2018, 11:37am UTC](https://discuss.elastic.co/t/logstash-timstamp-dateparsefailure-issue/127314 "2018-04-09T11:37:32Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![vincent25](https://avatars.discourse-cdn.com/v4/letter/v/71c47a/32.png) [@vincent25](https://discuss.elastic.co/u/vincent25)
#### Post date: [April 9, 2018, 11:37am UTC](https://discuss.elastic.co/t/logstash-timstamp-dateparsefailure-issue/127314/1 "2018-04-09T11:37:32Z")

</div>

Hi,  
I need to replace my log timestamp with logstash @timestamp.I have tried all possible ways and time formats but still not able to replace it and getting dateparsefailure issue every time.  
Can anybody help me to sort out this?  
Thanks in advance.

One line of my log sample is:  
[ERROR@[140598203889408]2018-01-23 06:43:48.798511 in src/TMSInfo.cpp(1699)]TMSInfo::GetCorrelationKey: CIN is NULL failed to create corr key based on cin

My pipeline:

input {  
file {  
path =\> [""x:\x\x\x.log""]  
start\_position =\> beginning  
}  
}

filter {  
grok {  
match =\> { "message" =\> "%{GREEDYDATA}%{TIMESTAMP\_ISO8601:msg} %{GREEDYDATA}"}  
}  
date {  
locale =\> "en"  
match =\> ["msg", "yyyy-MM-dd HH:mm:ss.S" ,"ISO8601" , " yyyy-MM-dd HH:mm:ss" , "yyyy-MM-dd HH:mm:ss.SSSSS" , "yyyy-mm-dd hh:mm:ss.S"]  
target =\> "@timestamp"  
add\_field =\> { "debug" =\> "timestampMatched"}  
}  
}

output {  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [April 9, 2018, 11:51am UTC](https://discuss.elastic.co/t/logstash-timstamp-dateparsefailure-issue/127314/2 "2018-04-09T11:51:36Z")

</div>

Did you try a date pattern ending with SSSSSS to capture the microseconds? I'm not sure that's supported so if it doesn't work you might have to cut them off with a mutate filter. What's printed by the `stdout { codec => rubydebug }` output?

---

<div class="post-metadata">

### Author: ![vincent25](https://avatars.discourse-cdn.com/v4/letter/v/71c47a/32.png) [@vincent25](https://discuss.elastic.co/u/vincent25)
#### Post date: [April 9, 2018, 12:09pm UTC](https://discuss.elastic.co/t/logstash-timstamp-dateparsefailure-issue/127314/3 "2018-04-09T12:09:46Z")

</div>

Hi,I tried,but did not work out.  
The output is like as below:  
{  
"path" =\> "x:\x\x\x.log",  
"@timestamp" =\> 2018-04-09T12:08:27.328Z,  
"@version" =\> "1",  
"host" =\> "CT-IL0004",  
"message" =\> "",  
"tags" =\> [  
[0] "\_grokparsefailure"  
]  
}

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [April 9, 2018, 12:16pm UTC](https://discuss.elastic.co/t/logstash-timstamp-dateparsefailure-issue/127314/4 "2018-04-09T12:16:52Z")

</div>

But in this case the message was empty.

---

<div class="post-metadata">

### Author: ![vincent25](https://avatars.discourse-cdn.com/v4/letter/v/71c47a/32.png) [@vincent25](https://discuss.elastic.co/u/vincent25)
#### Post date: [April 9, 2018, 12:20pm UTC](https://discuss.elastic.co/t/logstash-timstamp-dateparsefailure-issue/127314/5 "2018-04-09T12:20:38Z")

</div>

Take this output entry:  
{  
"path" =\> "x:\x\x\x.log",  
"@timestamp" =\> 2018-04-09T12:13:03.191Z,  
"@version" =\> "1",  
"host" =\> "CT-IL0004",  
"message" =\> " 2018-01-23 00:05:06.807734 : 1100023::CtRddmSocketDataSender::Connect: Re-initiating connection",  
"tags" =\> [  
[0] "\_grokparsefailure",  
[1] "\_dateparsefailure"  
]  
}

---

<div class="post-metadata">

### Author: ![vincent25](https://avatars.discourse-cdn.com/v4/letter/v/71c47a/32.png) [@vincent25](https://discuss.elastic.co/u/vincent25)
#### Post date: [April 9, 2018, 12:24pm UTC](https://discuss.elastic.co/t/logstash-timstamp-dateparsefailure-issue/127314/6 "2018-04-09T12:24:18Z")

</div>

Or take this output in which I did not remove "msg" log time stamp.The date format is same here:

{  
"msg" =\> "18-01-23 00:08:57.443820",  
"path" =\> "x:\x\x\x.log",  
"@timestamp" =\> 2018-04-09T12:21:52.594Z,  
"@version" =\> "1",  
"host" =\> "CT-IL0004",  
"message" =\> " 2018-01-23 00:08:57.443820 : 1100023::CtRddmSocketDataSender::Connect: Connect error 113 ",  
"tags" =\> [  
[0] "\_dateparsefailure"  
]  
}

---

<div class="post-metadata">

### Author: ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)
#### Post date: [April 9, 2018, 12:54pm UTC](https://discuss.elastic.co/t/logstash-timstamp-dateparsefailure-issue/127314/7 "2018-04-09T12:54:43Z")

</div>

Your grok cuts off the start of the timestamp, so it's actually 'yy', but Magnus' 'SSSSSS' suggestion works fine for me. The pattern "yy-MM-dd HH:mm:ss.SSSSSS" results in:

> ```
> "msg" => "18-01-23 06:43:48.798511",
> "@timestamp" => 2018-01-23T05:43:48.798Z,
> "testmsg" => "[ERROR@[140598203889408]2018-01-23 06:43:48.798511 in src/TMSInfo.cpp(1699)]TMSInfo::GetCorrelationKey: CIN is NULL failed to create corr key based on cin"
> 
> ```

and

> ```
> "msg" => "18-01-23 00:08:57.443820",
> "@timestamp" => 2018-01-22T23:08:57.443Z,
> "testmsg" => " 2018-01-23 00:08:57.443820 : 1100023::CtRddmSocketDataSender::Connect: Connect error 113 "
> 
> ```

---

<div class="post-metadata">

### Author: ![vincent25](https://avatars.discourse-cdn.com/v4/letter/v/71c47a/32.png) [@vincent25](https://discuss.elastic.co/u/vincent25)
#### Post date: [April 11, 2018, 6:34am UTC](https://discuss.elastic.co/t/logstash-timstamp-dateparsefailure-issue/127314/8 "2018-04-11T06:34:43Z")

</div>

Hi,  
Thank you so much to both of you.Its working fine now and serving my requirement.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 9, 2018, 6:34am UTC](https://discuss.elastic.co/t/logstash-timstamp-dateparsefailure-issue/127314/9 "2018-05-09T06:34:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
