# Mysterious \_dateparsefailure on identical fields

**URL:** <https://discuss.elastic.co/t/mysterious-dateparsefailure-on-identical-fields/240597>\
**Category:** Logstash\
**Created:** [July 9, 2020, 7:43pm UTC](https://discuss.elastic.co/t/mysterious-dateparsefailure-on-identical-fields/240597 "2020-07-09T19:43:52Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![pgervais](https://avatars.discourse-cdn.com/v4/letter/p/65b543/32.png) [@pgervais](https://discuss.elastic.co/u/pgervais)\
**Post date:** [July 9, 2020, 7:43pm UTC](https://discuss.elastic.co/t/mysterious-dateparsefailure-on-identical-fields/240597/1 "2020-07-09T19:43:52Z")

</div>

I have included below 3 csv input lines that are virtually identical to one another. The date field in the first and last parse properly whereas I get a \_dateparsefailure on the middle line.

The logstash date field is shown below.  
date {  
match =\> ["timestamp", "ddMMMyy:H", "ddMMMyy:HH"]  
target =\> "@timestamp"  
}

Line which starts with "1379" is the one that fails.

"1378","Commercial","eManPortl","CB\_AX01A","MDB-Cntr","mdb DAATradeDoc","08MAR15",1,5,0.00,0.00,0.01,1.72,6.73,0.03,0.00011,0.00,0.03,0.00,0.00,0.00,0.00,0.00,0.070441,0.056069,".",".",0.145431,0.000545,0.000473,0.143660,0.000753,0.01,8.45

"1379","Commercial","eManPortl","CB\_AX01A","MDB-Cntr","mdb DAATradeDoc","08MAR15",2,3,0.00,0.00,0.01,1.97,7.51,0.04,0.00013,0.00,0.04,0.00,0.00,0.00,0.00,0.00,0.047428,0.037567,".",".",0.108691,0.000377,0.000471,0.107275,0.000568,0.01,9.49

"1380","Commercial","eManPortl","CB\_AX01A","MDB-Cntr","mdb DAATradeDoc","08MAR15",3,1,0.00,0.00,0.00,1.96,8.19,0.05,0.00013,0.00,0.05,0.00,0.00,0.00,0.00,0.00,0.016913,0.013649,".",".",0.048059,0.000126,0.000127,0.047573,0.000233,0.00,10.15

If anyone can identify the reason for the failure it would be highly appreciated.

Pete Gervais

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 9, 2020, 7:46pm UTC](https://discuss.elastic.co/t/mysterious-dateparsefailure-on-identical-fields/240597/2 "2020-07-09T19:46:19Z")

</div>

Is the hour part 2 AM? That did not exist on 2015/3/8. DST started and we went straight from 1:59:59 to 3:00:00. See [here](https://discuss.elastic.co/t/logstash-date-function-mapping-timestamp-ends-with-error-dateparsefailure-when-a-hour-is-02/227679/5) for a possible solution.

---

<div class="post-metadata">

**Author:** ![pgervais](https://avatars.discourse-cdn.com/v4/letter/p/65b543/32.png) [@pgervais](https://discuss.elastic.co/u/pgervais)\
**Post date:** [July 9, 2020, 7:53pm UTC](https://discuss.elastic.co/t/mysterious-dateparsefailure-on-identical-fields/240597/3 "2020-07-09T19:53:28Z")

</div>

I have many lines in the csv file that has similar hour input which dont fail.  
I'm using logstash 7.4.0.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 9, 2020, 8:06pm UTC](https://discuss.elastic.co/t/mysterious-dateparsefailure-on-identical-fields/240597/4 "2020-07-09T20:06:41Z")

</div>

Are you asserting that "08MAR15:2" will sometimes be parsed and sometimes get a \_dateparsefailure?

---

<div class="post-metadata">

**Author:** ![pgervais](https://avatars.discourse-cdn.com/v4/letter/p/65b543/32.png) [@pgervais](https://discuss.elastic.co/u/pgervais)\
**Post date:** [July 9, 2020, 8:41pm UTC](https://discuss.elastic.co/t/mysterious-dateparsefailure-on-identical-fields/240597/5 "2020-07-09T20:41:55Z")

</div>

Badger,  
I have used your answer on selectively printing errors to run through all my input.  
Now I only see the errors and low and behold, all failures are on a date field that looks :  
"08MAR15",2 where hour == 2.

Does version 7.8.0 of logstash solve this issue out of the box or must I still do some special processing?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 9, 2020, 8:53pm UTC](https://discuss.elastic.co/t/mysterious-dateparsefailure-on-identical-fields/240597/6 "2020-07-09T20:53:22Z")

</div>

There is nothing elastic can do to fix that. That time did not occur that day. You need to decide what you want to do with times for that day (which only had 23 hours). You may also need to think about November 1, 2015, which had 25 hours. Depending on your exact use case that may or may not matter.

---

<div class="post-metadata">

**Author:** ![pgervais](https://avatars.discourse-cdn.com/v4/letter/p/65b543/32.png) [@pgervais](https://discuss.elastic.co/u/pgervais)\
**Post date:** [July 9, 2020, 8:53pm UTC](https://discuss.elastic.co/t/mysterious-dateparsefailure-on-identical-fields/240597/7 "2020-07-09T20:53:48Z")

</div>

Badger,  
As additional data , I have installed Version 7.8.0 and I still get the same error.  
There are many entries that contain the second hour of the i.e. 2 but it only happen when the date is "08MAR15".

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 6, 2020, 8:53pm UTC](https://discuss.elastic.co/t/mysterious-dateparsefailure-on-identical-fields/240597/8 "2020-08-06T20:53:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
