# Multiple Date fields in logstash

**URL:** <https://discuss.elastic.co/t/multiple-date-fields-in-logstash/25213>\
**Category:** Logstash\
**Created:** [July 9, 2015, 7:29am UTC](https://discuss.elastic.co/t/multiple-date-fields-in-logstash/25213 "2015-07-09T07:29:51Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![sanju1323](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@sanju1323](https://discuss.elastic.co/u/sanju1323)\
**Post date:** [July 9, 2015, 7:29am UTC](https://discuss.elastic.co/t/multiple-date-fields-in-logstash/25213/1 "2015-07-09T07:29:51Z")

</div>

Hi,

I have a small query regarding date field.

In my data file there are two date fields like  
submit\_date : 2012-12-22 12:53:30.000  
release\_date: 2012-12-31 12:53:30.000

for this I tried using the following in the logstash configuration file.

date {  
locale =\> "en"  
match =\> ["submit\_date", "YYYY-MM-dd HH:mm:ss.SSS"]  
}

date {  
locale =\> "en"  
match =\> ["release\_date", "YYYY-MM-dd HH:mm:ss.SSS"]  
}

But still it is considering only submit date and release\_date is showing as string.

I want to take both submit\_date and release\_date in the date format.

Please help

Thanks & Regards,  
Sanjay Reddy

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 9, 2015, 7:38am UTC](https://discuss.elastic.co/t/multiple-date-fields-in-logstash/25213/2 "2015-07-09T07:38:49Z")

</div>

By default the date filter stores the result of the parsing in the `@timestamp` field. If you want it stored elsewhere you need to set the filter's `target` parameter.

---

<div class="post-metadata">

**Author:** ![sanju1323](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@sanju1323](https://discuss.elastic.co/u/sanju1323)\
**Post date:** [July 9, 2015, 9:15am UTC](https://discuss.elastic.co/t/multiple-date-fields-in-logstash/25213/3 "2015-07-09T09:15:10Z")

</div>

@magnusbaeck Can you please give an example to set the filter's target parameter for date

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 9, 2015, 9:58am UTC](https://discuss.elastic.co/t/multiple-date-fields-in-logstash/25213/4 "2015-07-09T09:58:22Z")

</div>

```
date {
  match => ["submit_date", "YYYY-MM-dd HH:mm:ss.SSS"]
  target => "submit_date"
}
```

---

<div class="post-metadata">

**Author:** ![sanju1323](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@sanju1323](https://discuss.elastic.co/u/sanju1323)\
**Post date:** [July 9, 2015, 10:43am UTC](https://discuss.elastic.co/t/multiple-date-fields-in-logstash/25213/5 "2015-07-09T10:43:30Z")

</div>

Thanks @magnusbaeck that worked...  
Thankyou very much 😄

---

<div class="post-metadata">

**Author:** ![sanju1323](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@sanju1323](https://discuss.elastic.co/u/sanju1323)\
**Post date:** [July 9, 2015, 2:32pm UTC](https://discuss.elastic.co/t/multiple-date-fields-in-logstash/25213/6 "2015-07-09T14:32:32Z")

</div>

@magnusbaeck

As suggested I have added another date field with target parameter in the logstash.conf file.

If there is null in the "ReleaseDate" those logs are not indexing. Because of that only few records are indexing and the remaining records are not indexing. But I want all the records to be indexed.

Can you please help in this.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 10, 2015, 5:52am UTC](https://discuss.elastic.co/t/multiple-date-fields-in-logstash/25213/7 "2015-07-10T05:52:01Z")

</div>

If certain messages are dropped I doubt it's related to a "null" ReleaseDate field (do you mean a missing field?), but you can use a conditional to only use the date filter when the field is set.

```
if [ReleaseDate] {
  date {
    ...
  }
}

```

If you still have problems please provide a complete example that exhibits your problem.

---

<div class="post-metadata">

**Author:** ![L2W](https://avatars.discourse-cdn.com/v4/letter/l/8dc957/32.png) [@L2W](https://discuss.elastic.co/u/L2W)\
**Post date:** [October 23, 2015, 8:14pm UTC](https://discuss.elastic.co/t/multiple-date-fields-in-logstash/25213/8 "2015-10-23T20:14:03Z")

</div>

I have a very similar question about having multiple dates in my data.

I have a Start\_Date\_Time and an End\_Date\_Time. If I use the date plugin to shove both of them into the @timestamp so I can convert them both with the target option to store them as date/times in the data instead of strings (thanks for that tip, since it was what I was looking for), which @timestamp goes into ElasticSearch or do they both go in as two different @timestamps? I'm assuming the last one in the code would be the one stored as typically code overwrites previous code; however, want to be sure before changing the logstash files that I've inherited since this could really muck up my data if I get it wrong. Thanks in advance!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 25, 2015, 9:34am UTC](https://discuss.elastic.co/t/multiple-date-fields-in-logstash/25213/9 "2015-10-25T09:34:35Z")

</div>

@L2W, please post unrelated questions in new topics.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:25am UTC](https://discuss.elastic.co/t/multiple-date-fields-in-logstash/25213/10 "2017-07-06T05:25:30Z")

</div>


