# Match timestamps using different locales

**URL:** <https://discuss.elastic.co/t/match-timestamps-using-different-locales/122219>\
**Category:** Logstash\
**Created:** [March 2, 2018, 9:51am UTC](https://discuss.elastic.co/t/match-timestamps-using-different-locales/122219 "2018-03-02T09:51:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![friesoft](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/friesoft/32/23388_2.png) [@friesoft](https://discuss.elastic.co/u/friesoft)\
**Post date:** [March 2, 2018, 9:51am UTC](https://discuss.elastic.co/t/match-timestamps-using-different-locales/122219/1 "2018-03-02T09:51:20Z")

</div>

Hi,

we have some logfiles which contain three different timestamp formats.  
Example:

> [02/M **a** r/2018:09:35:21] [Info] [Module] [3085] [Function] my message  
> [Fri Mar 02 09:35:21.474812 2018] [Module] [pid 1819:tid 140437688055616] errorcode: caught SIGTERM, shutting down  
> [02/M **ä** r/2018:09:35:25] [Info] [Module] [19154] [Function: message]

The timestamp is always contained in the field "timestamp", extracted using a grok pattern.

I've tried the following:

> ```
> date {
> match => ["timestamp", "dd/MMM/yyyy:HH:mm:ss"] # 02/Mar/2018:09:35:21
> locale => ["en-US"]
> }
> date {
> match => ["timestamp", "dd/MMM/yyyy:HH:mm:ss"] # 02/Mär/2018:09:35:25
> locale => ["de-DE"]
> }
> date {
> match => ["timestamp", "EEE MMM dd HH:mm:ss.SSSSSS yyyy"] # Fri Mar 02 09:35:30.052734 2018
> }
> 
> ```

The problem is: I get dateparsefailure on all three lines. How to get rid of those? The timestamps themselves are correctly parsed.

What would be the correct way to handle such special logfiles?..

Thanks  
Bernhard

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 2, 2018, 12:45pm UTC](https://discuss.elastic.co/t/match-timestamps-using-different-locales/122219/2 "2018-03-02T12:45:34Z")

</div>

You can clear the date filter's `tag_on_failure` option to avoid the `_dateparsefailure` tag. If you want to keep that tag if _none_ of the filters matched that's possible but will require a bunch of conditionals and probably a few mutate filters.

---

<div class="post-metadata">

**Author:** ![friesoft](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/friesoft/32/23388_2.png) [@friesoft](https://discuss.elastic.co/u/friesoft)\
**Post date:** [March 2, 2018, 2:44pm UTC](https://discuss.elastic.co/t/match-timestamps-using-different-locales/122219/3 "2018-03-02T14:44:18Z")

</div>

Thanks for the info! 🙂 didn't grasp that tag\_on\_failure was the right thing for me 🙂  
Works for me now.

I just noticed one of the patterns is still wrong - the time contains microseconds - which it looks like can't be parsed using logstash/jodatime.  
What can I do to match the rest of the date/time?

> Fri Mar 02 10:03:03.048488 2018

> ```
> date {
> match => ["timestamp", "EEE MMM dd HH:mm:ss.SSS **SSS** yyyy"]
> tag_on_failure => []
> }
> 
> ```

Thanks for the fast reply 🙂

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 2, 2018, 3:20pm UTC](https://discuss.elastic.co/t/match-timestamps-using-different-locales/122219/4 "2018-03-02T15:20:13Z")

</div>

You might have to use a mutate filter's gsub option to remove the microseconds. The date filter doesn't keep more than millisecond precision anyway.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2018, 3:20pm UTC](https://discuss.elastic.co/t/match-timestamps-using-different-locales/122219/5 "2018-03-30T15:20:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
