# Need help with the grok and the date filter for parsing logs

**URL:** <https://discuss.elastic.co/t/need-help-with-the-grok-and-the-date-filter-for-parsing-logs/86523>\
**Category:** Logstash\
**Created:** [May 20, 2017, 11:57am UTC](https://discuss.elastic.co/t/need-help-with-the-grok-and-the-date-filter-for-parsing-logs/86523 "2017-05-20T11:57:38Z")\
**Posts on this page:** 10\
**Page:** 2

<div class="post-metadata">

**Author:** ![Gaurav\_Singh1](https://avatars.discourse-cdn.com/v4/letter/g/edb3f5/32.png) [@Gaurav\_Singh1](https://discuss.elastic.co/u/Gaurav_Singh1)\
**Post date:** [June 2, 2017, 1:33pm UTC](https://discuss.elastic.co/t/need-help-with-the-grok-and-the-date-filter-for-parsing-logs/86523/21 "2017-06-02T13:33:45Z")

</div>

Below is the json one :

{  
"\_index": "splunk",  
"\_type": "logs",  
"\_id": "AVxn5KYXN2Qa6z\_B1oMa",  
"\_score": 1,  
"\_source": {  
"Status": "Resolved",  
"Message2": "1",  
"Message1": "Up",  
"ConfigItem": "[nypl-mt4.iii.com](http://nypl-mt4.iii.com)",  
"Time": "Monday, May 15, 2017 12:54 PM",  
"Severity": "Warning",  
"message": "Time=Monday, May 15, 2017 12:54 PM;Source=APM;Status=Resolved;Severity=Warning;Location=SYRDC-TO;[ConfigItem=nypl-mt4.iii.com](http://ConfigItem=nypl-mt4.iii.com);Alert=III-TO - HTTP Check for Encore;Message1=Up;Message2=1",  
"Source": "APM",  
"path": "/opt/capital.log",  
"@timestamp": "2017-05-15T12:54:00.000Z",  
"@version": "1",  
"host": "b3b3ecef78ac",  
"Alert": "III-TO - HTTP Check for Encore",  
"Location": "SYRDC-TO"  
},  
"fields": {  
"@timestamp": [  
1494852840000  
]  
}  
}

And this is from the table one :

@timestamp May 15th 2017, 18:24:00.000  
t @version 1  
t Alert III-TO - HTTP Check for Encore  
t ConfigItem [nypl-mt4.iii.com](http://nypl-mt4.iii.com)  
t Location SYRDC-TO  
t Message1 Up  
t Message2 1  
t Severity Warning  
t Source APM  
t Status Resolved  
t Time Monday, May 15, 2017 12:54 PM  
t \_id AVxn5KYXN2Qa6z\_B1oMa  
t \_index splunk

# \_score 1

t \_type logs  
t host b3b3ecef78ac  
t message Time=Monday, May 15, 2017 12:54 PM;Source=APM;Status=Resolved;Severity=Warning;Location=SYRDC-TO;[ConfigItem=nypl-mt4.iii.com](http://ConfigItem=nypl-mt4.iii.com);Alert=III-TO - HTTP Check for Encore;Message1=Up;Message2=1  
t path /opt/capital.log

---

<div class="post-metadata">

**Author:** ![Gaurav\_Singh1](https://avatars.discourse-cdn.com/v4/letter/g/edb3f5/32.png) [@Gaurav\_Singh1](https://discuss.elastic.co/u/Gaurav_Singh1)\
**Post date:** [June 2, 2017, 1:34pm UTC](https://discuss.elastic.co/t/need-help-with-the-grok-and-the-date-filter-for-parsing-logs/86523/22 "2017-06-02T13:34:35Z")

</div>

these logs are in PST and I am in IST.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 2, 2017, 1:47pm UTC](https://discuss.elastic.co/t/need-help-with-the-grok-and-the-date-filter-for-parsing-logs/86523/23 "2017-06-02T13:47:20Z")

</div>

If the logs are PST (I actually think you mean PDT) then "Monday, May 15, 2017 12:54" should be transformed to 2017-05-15T19:54Z. Perhaps the timezone isn't correctly set in your Docker container? You can use the date filter's `timezone` option to force it to America/Los\_Angeles or whatever is most appropriate in your case.

---

<div class="post-metadata">

**Author:** ![Gaurav\_Singh1](https://avatars.discourse-cdn.com/v4/letter/g/edb3f5/32.png) [@Gaurav\_Singh1](https://discuss.elastic.co/u/Gaurav_Singh1)\
**Post date:** [June 27, 2017, 10:50am UTC](https://discuss.elastic.co/t/need-help-with-the-grok-and-the-date-filter-for-parsing-logs/86523/24 "2017-06-27T10:50:04Z")

</div>

Hi Magnus,

Need help on the input of logstash , as I want to visualize performance data of solarwind server in real time.

What would be the possible choices for getting the data as input in logstash ? (As solarwind is a windows server and my ELK stack is running on docker on a centos7 machine)

Regards,  
Gaurav Singh

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 27, 2017, 11:34am UTC](https://discuss.elastic.co/t/need-help-with-the-grok-and-the-date-filter-for-parsing-logs/86523/25 "2017-06-27T11:34:06Z")

</div>

You could use Filebeat on the Windows machine to ship the log files to Logstash.

---

<div class="post-metadata">

**Author:** ![Gaurav\_Singh1](https://avatars.discourse-cdn.com/v4/letter/g/edb3f5/32.png) [@Gaurav\_Singh1](https://discuss.elastic.co/u/Gaurav_Singh1)\
**Post date:** [June 27, 2017, 12:15pm UTC](https://discuss.elastic.co/t/need-help-with-the-grok-and-the-date-filter-for-parsing-logs/86523/26 "2017-06-27T12:15:50Z")

</div>

Will it work in real time as well ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 27, 2017, 12:23pm UTC](https://discuss.elastic.co/t/need-help-with-the-grok-and-the-date-filter-for-parsing-logs/86523/27 "2017-06-27T12:23:53Z")

</div>

Yes.

---

<div class="post-metadata">

**Author:** ![Gaurav\_Singh1](https://avatars.discourse-cdn.com/v4/letter/g/edb3f5/32.png) [@Gaurav\_Singh1](https://discuss.elastic.co/u/Gaurav_Singh1)\
**Post date:** [June 27, 2017, 2:47pm UTC](https://discuss.elastic.co/t/need-help-with-the-grok-and-the-date-filter-for-parsing-logs/86523/28 "2017-06-27T14:47:00Z")

</div>

Can we go with the Winscp option ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 27, 2017, 2:56pm UTC](https://discuss.elastic.co/t/need-help-with-the-grok-and-the-date-filter-for-parsing-logs/86523/29 "2017-06-27T14:56:54Z")

</div>

I don't know what "the Winscp option" means.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 25, 2017, 2:56pm UTC](https://discuss.elastic.co/t/need-help-with-the-grok-and-the-date-filter-for-parsing-logs/86523/30 "2017-07-25T14:56:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

[Previous page](https://discuss.elastic.co/t/need-help-with-the-grok-and-the-date-filter-for-parsing-logs/86523.md?page=1)
