# Not able to convert the Grokked value to timestamp

**URL:** <https://discuss.elastic.co/t/not-able-to-convert-the-grokked-value-to-timestamp/72115>\
**Category:** Logstash\
**Created:** [January 19, 2017, 5:59am UTC](https://discuss.elastic.co/t/not-able-to-convert-the-grokked-value-to-timestamp/72115 "2017-01-19T05:59:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Prateek\_Kshtriya](https://avatars.discourse-cdn.com/v4/letter/p/c37758/32.png) [@Prateek\_Kshtriya](https://discuss.elastic.co/u/Prateek_Kshtriya)\
**Post date:** [January 19, 2017, 5:59am UTC](https://discuss.elastic.co/t/not-able-to-convert-the-grokked-value-to-timestamp/72115/1 "2017-01-19T05:59:20Z")

</div>

Hi All,

I am trying to capture the time in the below message-

02 Sep 2016 06:31:03:Master: WARNING - \>: OL:0-1232 GHOW: error found in waiting table:

Problem 1- The time stamp is not getting picked by "DATESTAMP" grok command so %{WORD}-%{MONTH}-%{YEAR} %{TIME} is used to pick the value. Please help how to use %{DAY} instead of %{WORD} as it leads to problem 2

Problem 2- When trying to convert to date format using   
date {  
match =\> ["timestamp", "dd M yy HH:mm:ss"]  
}

It is giving below error while posting data using logstash -

Failed parsing date from field {:field=\>"timestamp", :value=\>"02 Sep 2016 1  
6:52:39", :exception=\>"Invalid format: "02 Sep 2016 16:52:39" is malformed at  
"Sep 2016 16:52:39"", :config\_parsers=\>"dd M yy HH:mm:ss", :config\_locale=\>"de  
fault=en\_US", :level=\>:warn}

Please help with same.

Regards,  
Prateek

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 19, 2017, 7:18am UTC](https://discuss.elastic.co/t/not-able-to-convert-the-grokked-value-to-timestamp/72115/2 "2017-01-19T07:18:08Z")

</div>

> Please help how to use %{DAY} instead of %{WORD}

DAY is the name of the weekday. You should use MONTHDAY.

> as it leads to problem 2

No, your use of WORD is unrelated to your second problem.

> match =\> ["timestamp", "dd M yy HH:mm:ss"]

Try MMM instead of M and yyyy instead of yy.

---

<div class="post-metadata">

**Author:** ![Prateek\_Kshtriya](https://avatars.discourse-cdn.com/v4/letter/p/c37758/32.png) [@Prateek\_Kshtriya](https://discuss.elastic.co/u/Prateek_Kshtriya)\
**Post date:** [January 19, 2017, 9:36am UTC](https://discuss.elastic.co/t/not-able-to-convert-the-grokked-value-to-timestamp/72115/3 "2017-01-19T09:36:34Z")

</div>

Thank you. The solution resolves the issue.

Regards,  
Prateek Divya

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 16, 2017, 9:36am UTC](https://discuss.elastic.co/t/not-able-to-convert-the-grokked-value-to-timestamp/72115/4 "2017-02-16T09:36:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
