# Parse string to timestamp in csv

**URL:** <https://discuss.elastic.co/t/parse-string-to-timestamp-in-csv/171408>\
**Category:** Logstash\
**Created:** [March 8, 2019, 1:47am UTC](https://discuss.elastic.co/t/parse-string-to-timestamp-in-csv/171408 "2019-03-08T01:47:00Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![scorpioy1](https://avatars.discourse-cdn.com/v4/letter/s/e47c2d/32.png) [@scorpioy1](https://discuss.elastic.co/u/scorpioy1)\
**Post date:** [March 8, 2019, 1:47am UTC](https://discuss.elastic.co/t/parse-string-to-timestamp-in-csv/171408/1 "2019-03-08T01:47:00Z")

</div>

Hi, I'm trying to parse the 1st column of line in csv to be a timestamp column. But elasticsearch is still treating it as string, not a timestamp. Please help.

filter {  
csv {  
columns =\> ["nowdatetime","Total\_sum","DIFF"]  
convert =\> {  
"Total\_sum" =\> "integer"  
"DIFF" =\> "integer"  
}  
}  
date {  
match =\> ["nowdatetime", "yyyy-MM-dd'T'HH:mm:ss'.'SSS"]  
target =\> "nowdatetime"  
}  
}

Where is it wrong in this logstash?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 8, 2019, 1:45pm UTC](https://discuss.elastic.co/t/parse-string-to-timestamp-in-csv/171408/2 "2019-03-08T13:45:35Z")

</div>

Do you get a \_dateparsefailure tag? If so, what does the nowdatetime field look like? If not, then the mapping of the field in elasticsearch is string, that's not going to change for the current index. If you start over with a new index does it get mapped as a date?

---

<div class="post-metadata">

**Author:** ![scorpioy1](https://avatars.discourse-cdn.com/v4/letter/s/e47c2d/32.png) [@scorpioy1](https://discuss.elastic.co/u/scorpioy1)\
**Post date:** [March 8, 2019, 3:30pm UTC](https://discuss.elastic.co/t/parse-string-to-timestamp-in-csv/171408/3 "2019-03-08T15:30:09Z")

</div>

Ok, I deleted the index. The nowdatetime does get the value like '2019-03-08 10:25:17.105' but it's a string, not a timestamp.  
When I import it from Kibana, Kibana only recognizes the default @timestamp as the only selection in 'Time Filter field name'. I want 'nowdatetime' to be an option from here.

What should I change?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 8, 2019, 3:33pm UTC](https://discuss.elastic.co/t/parse-string-to-timestamp-in-csv/171408/4 "2019-03-08T15:33:27Z")

</div>

'2019-03-08 10:25:17.105' does not match the format in your date filter.

---

<div class="post-metadata">

**Author:** ![scorpioy1](https://avatars.discourse-cdn.com/v4/letter/s/e47c2d/32.png) [@scorpioy1](https://discuss.elastic.co/u/scorpioy1)\
**Post date:** [March 8, 2019, 3:40pm UTC](https://discuss.elastic.co/t/parse-string-to-timestamp-in-csv/171408/5 "2019-03-08T15:40:51Z")

</div>

Got it... I had an extra T in it.

---

<div class="post-metadata">

**Author:** ![scorpioy1](https://avatars.discourse-cdn.com/v4/letter/s/e47c2d/32.png) [@scorpioy1](https://discuss.elastic.co/u/scorpioy1)\
**Post date:** [March 8, 2019, 3:43pm UTC](https://discuss.elastic.co/t/parse-string-to-timestamp-in-csv/171408/6 "2019-03-08T15:43:12Z")

</div>

In my logstash logs, I found

"nowdatetime" =\> 2019-03-08T15:41:17.960Z,

In the Kibana, I got March 8th 2019, 10:40:17.916

What are those 'T' and 'Z' in the logstash?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 8, 2019, 4:00pm UTC](https://discuss.elastic.co/t/parse-string-to-timestamp-in-csv/171408/7 "2019-03-08T16:00:36Z")

</div>

Still does not match. Try

```
    date {
        match => ["nowdatetime", "yyyy-MM-dd'T'HH:mm:ss.SSS'Z'"]
        target => "nowdatetime"
    }
```

---

<div class="post-metadata">

**Author:** ![scorpioy1](https://avatars.discourse-cdn.com/v4/letter/s/e47c2d/32.png) [@scorpioy1](https://discuss.elastic.co/u/scorpioy1)\
**Post date:** [March 8, 2019, 4:20pm UTC](https://discuss.elastic.co/t/parse-string-to-timestamp-in-csv/171408/8 "2019-03-08T16:20:30Z")

</div>

I changed to match =\> ["nowdatetime", "yyyy-MM-dd' 'HH:mm:ss'.'SSS"] and it works. The col is now a timestamp type.

Here is a line from my csv  
2019-03-08 11:02:19.08, 0, 0

I had the 'T' in the expression and logstash treat the col to string. My timestamp values doesn't have 'Z' either.

I don't understand why logstash would print logs containing 'T' and 'Z'.  
"nowdatetime" =\> 2019-03-08T15:41:17.960Z

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 8, 2019, 4:38pm UTC](https://discuss.elastic.co/t/parse-string-to-timestamp-in-csv/171408/9 "2019-03-08T16:38:31Z")

</div>

> [@scorpioy1](#):
>
> I don't understand why logstash would print logs containing 'T' and 'Z'.  
> "nowdatetime" =\> 2019-03-08T15:41:17.960Z

It's the [ISO 8601](https://en.wikipedia.org/wiki/ISO_8601) format.

---

<div class="post-metadata">

**Author:** ![scorpioy1](https://avatars.discourse-cdn.com/v4/letter/s/e47c2d/32.png) [@scorpioy1](https://discuss.elastic.co/u/scorpioy1)\
**Post date:** [March 8, 2019, 4:43pm UTC](https://discuss.elastic.co/t/parse-string-to-timestamp-in-csv/171408/10 "2019-03-08T16:43:30Z")

</div>

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2019, 4:43pm UTC](https://discuss.elastic.co/t/parse-string-to-timestamp-in-csv/171408/11 "2019-04-05T16:43:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
