# Parse different datetime values into timestamp

**URL:** <https://discuss.elastic.co/t/parse-different-datetime-values-into-timestamp/79029>\
**Category:** Logstash\
**Created:** [March 17, 2017, 1:18pm UTC](https://discuss.elastic.co/t/parse-different-datetime-values-into-timestamp/79029 "2017-03-17T13:18:21Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Grokster](https://avatars.discourse-cdn.com/v4/letter/g/ecd19e/32.png) [@Grokster](https://discuss.elastic.co/u/Grokster)\
**Post date:** [March 17, 2017, 1:18pm UTC](https://discuss.elastic.co/t/parse-different-datetime-values-into-timestamp/79029/1 "2017-03-17T13:18:21Z")

</div>

Hello, bare with me, I'm fairly new to the stack and have a simple question.

I have the following log lines in different files:

2017-03-17 22:25:04 My log

and sometimes:

2017-03-17 22:25:04,123 another log line...

I tried with something like this, which of course did not work;

```
	grok {
      patterns_dir => ["patterns_path"]
      match => { "message" => "(?:\s*)%{DATESTAMP:timestamp}(?:\s*)%{GREEDYDATA:Message}" }
  }
	date {
		match => ["timestamp", "yyyy-MM-dd HH:mm:ss", "yyyy-MM-dd HH:mm:ss,SSS", ISO8601]
		locale => "sv_SE"
	}
	mutate {
		add_field => {
			"timestamp" => logtime
		}
	}

```

Anyone care to shed som light into this?

---

<div class="post-metadata">

**Author:** ![paz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paz/32/28003_2.png) [@paz](https://discuss.elastic.co/u/paz)\
**Post date:** [March 17, 2017, 1:55pm UTC](https://discuss.elastic.co/t/parse-different-datetime-values-into-timestamp/79029/2 "2017-03-17T13:55:06Z")

</div>

I suppose you want to have the parsed timestamp in the "logtime" field?

Provided your grok pattern works fine, something like this should work.

`grok {
    patterns_dir => ["patterns_path"]
    match => { "message" => "(?:\s*)%{DATESTAMP:timestamp}(?:\s*)%{GREEDYDATA:Message}" }
}
date {
    match => ["timestamp", "yyyy-MM-dd HH:mm:ss", "yyyy-MM-dd HH:mm:ss,SSS", ISO8601]
    locale => "sv_SE"
    target => "logtime"
}`

No need for a mutate filter, which by the way the correct syntax is

`	mutate {
		add_field => {
			"field1_name" => %{field2_value}
		}
	}`

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 17, 2017, 1:57pm UTC](https://discuss.elastic.co/t/parse-different-datetime-values-into-timestamp/79029/3 "2017-03-17T13:57:04Z")

</div>

DATESTAMP is the wrong pattern. Try TIMESTAMP\_ISO8601 instead.

---

<div class="post-metadata">

**Author:** ![Grokster](https://avatars.discourse-cdn.com/v4/letter/g/ecd19e/32.png) [@Grokster](https://discuss.elastic.co/u/Grokster)\
**Post date:** [March 17, 2017, 2:35pm UTC](https://discuss.elastic.co/t/parse-different-datetime-values-into-timestamp/79029/4 "2017-03-17T14:35:17Z")

</div>

Thanks a lot, guys. I'm pleasantly surprised by the level of support here. I will definitely spread the word.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 14, 2017, 2:35pm UTC](https://discuss.elastic.co/t/parse-different-datetime-values-into-timestamp/79029/5 "2017-04-14T14:35:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
