# Logstash uses the time in the log to resolve to @timestamp, the parsing format in the match is disassembled, and a matching exception occurs!

**URL:** <https://discuss.elastic.co/t/logstash-uses-the-time-in-the-log-to-resolve-to-timestamp-the-parsing-format-in-the-match-is-disassembled-and-a-matching-exception-occurs/164305>\
**Category:** Logstash\
**Created:** [January 15, 2019, 12:08pm UTC](https://discuss.elastic.co/t/logstash-uses-the-time-in-the-log-to-resolve-to-timestamp-the-parsing-format-in-the-match-is-disassembled-and-a-matching-exception-occurs/164305 "2019-01-15T12:08:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sun\_changlong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sun_changlong/32/39036_2.png) [@sun\_changlong](https://discuss.elastic.co/u/sun_changlong)\
**Post date:** [January 15, 2019, 12:08pm UTC](https://discuss.elastic.co/t/logstash-uses-the-time-in-the-log-to-resolve-to-timestamp-the-parsing-format-in-the-match-is-disassembled-and-a-matching-exception-occurs/164305/1 "2019-01-15T12:08:01Z")

</div>

The format of the time field in the log:  
`version=1.0 time="2019-01-15 18:20:05" dev="WAF01.PUB.BEIJING-B" pri="0"`

Parsing in match:

```
date {
  #"time" => "2019-01-15 18:20:05"
  match => ["time", "yyyy-MM-dd HH:mm:ss"]
  target => "@timestamp"
  locale => "en"
}

```

I corresponded in time format, but the reported exception information only shows the format as time, minute, and second.

```
error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse [time]", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"Invalid format: \"2019-01-15 18:20:05\" is malformed at \" 18:20:05\""}

```

The normal format is considered to be:  
" 18:20:05"

Does anyone know why this was dismantled?  
I have seen the same problem encountered below, but did not make a reasonable explanation, my time is not Xia Li camp time.

> [@Date format rejected, no apparent reason why](https://discuss.elastic.co/t/date-format-rejected-no-apparent-reason-why/125082):
>
> Hello, I am trying to understand the following error: The main problem is at the bottom of the error: Invalid format: \"2018-03-11 02:48:31\" is malformed at \" 02:48:31\" [2018-03-21T15:59:35,601][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>"1995397226128", :\_index=\>"unifieddxcvpc", :\_type=\>"doc", :\_routing=\>nil}, #\<LogStash::Event:0x3863e85\>], :response=\>{"index"=\>{"\_index"=\>"unifieddxcvpc", "\_type"=\>"doc", "\_id"=\>"…

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 15, 2019, 2:35pm UTC](https://discuss.elastic.co/t/logstash-uses-the-time-in-the-log-to-resolve-to-timestamp-the-parsing-format-in-the-match-is-disassembled-and-a-matching-exception-occurs/164305/2 "2019-01-15T14:35:31Z")

</div>

This is really an elasticsearch question. The error is not logged by the date filter, it is logged by the elasticseach output. If you change the output to be stdout { codec =\> rubydebug } then I think you will see the timestamp was parsed OK.

I believe you could change the document mapping to accept that format, but as I said, it is an elasticsearch question.

---

<div class="post-metadata">

**Author:** ![sun\_changlong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sun_changlong/32/39036_2.png) [@sun\_changlong](https://discuss.elastic.co/u/sun_changlong)\
**Post date:** [January 16, 2019, 1:47am UTC](https://discuss.elastic.co/t/logstash-uses-the-time-in-the-log-to-resolve-to-timestamp-the-parsing-format-in-the-match-is-disassembled-and-a-matching-exception-occurs/164305/3 "2019-01-16T01:47:57Z")

</div>

This error message appears in the log of the logstash log, I use the stdout { codec =\> rubydebug } output. However, the corresponding index data is not generated in elasticsearch.

> [WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"test", :\_type=\>"udp\_test", :\_routing=\>nil}, #LogStash::Event:0x64ffbcdf], :response=\>{"index"=\>{"\_index"=\>"test", "\_type"=\>"udp\_test", "\_id"=\>"1AhKVGgBcZL-34tzTvzI", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse [time]", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"Invalid format: "2019-01-15 18:20:05" is malformed at " 18:20:05""}}}}}

```
"time" => "2019-01-15 18:20:05"

```

but the timestamp is

"@timestamp" =\> 2019-01-16T01:38:17.021Z

The data line is parsed by the kv plugin, and then the date processing is performed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 13, 2019, 1:48am UTC](https://discuss.elastic.co/t/logstash-uses-the-time-in-the-log-to-resolve-to-timestamp-the-parsing-format-in-the-match-is-disassembled-and-a-matching-exception-occurs/164305/4 "2019-02-13T01:48:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
