# Parsing a crappy date format

**URL:** <https://discuss.elastic.co/t/parsing-a-crappy-date-format/32263>\
**Category:** Logstash\
**Created:** [October 15, 2015, 11:19am UTC](https://discuss.elastic.co/t/parsing-a-crappy-date-format/32263 "2015-10-15T11:19:33Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aviv\_Ratzon](https://avatars.discourse-cdn.com/v4/letter/a/df788c/32.png) [@Aviv\_Ratzon](https://discuss.elastic.co/u/Aviv_Ratzon)\
**Post date:** [October 15, 2015, 11:19am UTC](https://discuss.elastic.co/t/parsing-a-crappy-date-format/32263/1 "2015-10-15T11:19:33Z")

</div>

Hi everyone,  
I have a real problem that I couldn't find a decent solution to.  
I need to parse log files and extract dates inside these files. the date format is really crappy and looks like this:

```
10/09/15 13:55:57:2020
DD/MM/YY HH:MM:SS:ssss

```

What would be a good way to parse it into a timestamp field? The date filter doesn't seem to provide a good solution to this.

thank you very much.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 15, 2015, 12:45pm UTC](https://discuss.elastic.co/t/parsing-a-crappy-date-format/32263/2 "2015-10-15T12:45:56Z")

</div>

Except for the absence of a timezone specifier there's nothing crappy about it, and the date filter is a perfect fit for this task.

---

<div class="post-metadata">

**Author:** ![Aviv\_Ratzon](https://avatars.discourse-cdn.com/v4/letter/a/df788c/32.png) [@Aviv\_Ratzon](https://discuss.elastic.co/u/Aviv_Ratzon)\
**Post date:** [October 15, 2015, 2:01pm UTC](https://discuss.elastic.co/t/parsing-a-crappy-date-format/32263/3 "2015-10-15T14:01:55Z")

</div>

So how come it fails to parse it? am I doing something wrong:

```
  date
  {
	match => ["logdate", "dd/MM/YY"]
  }

```

I've tried dozens of different configurations with this filter and it simply won't output any time fields.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 15, 2015, 2:06pm UTC](https://discuss.elastic.co/t/parsing-a-crappy-date-format/32263/4 "2015-10-15T14:06:16Z")

</div>

If the `logdate` field indeed contains "10/09/15 13:55:57:2020" you need a date pattern that includes the time. I suppose "dd/MM/YY HH:mm:ss:SSSS" should work.

---

<div class="post-metadata">

**Author:** ![Aviv\_Ratzon](https://avatars.discourse-cdn.com/v4/letter/a/df788c/32.png) [@Aviv\_Ratzon](https://discuss.elastic.co/u/Aviv_Ratzon)\
**Post date:** [October 15, 2015, 2:19pm UTC](https://discuss.elastic.co/t/parsing-a-crappy-date-format/32263/5 "2015-10-15T14:19:19Z")

</div>

I run this filter:

```
  date
  {
	match => ["time", "dd/MM/YY HH:mm:ss:SSSS"]
  }

```

with this input:

```
15/12/13 05:20:22:3333

```

and... nothing.  
Any idea what the problem is?

thank you very much for your help 🙂

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 15, 2015, 2:23pm UTC](https://discuss.elastic.co/t/parsing-a-crappy-date-format/32263/6 "2015-10-15T14:23:20Z")

</div>

Works fine for me:

```
$ cat test.config 
input { stdin { } }
output { stdout { codec => rubydebug } }
filter {
  date {
    match => ["message", "dd/MM/YY HH:mm:ss:SSSS"]
  }
}
$ echo 15/12/13 05:20:22:3333 | /opt/logstash/bin/logstash -f test.config
Logstash startup completed
{
       "message" => "15/12/13 05:20:22:3333",
      "@version" => "1",
    "@timestamp" => "2013-12-15T04:20:22.333Z",
          "host" => "lnxolofon"
}
Logstash shutdown completed
```

---

<div class="post-metadata">

**Author:** ![Aviv\_Ratzon](https://avatars.discourse-cdn.com/v4/letter/a/df788c/32.png) [@Aviv\_Ratzon](https://discuss.elastic.co/u/Aviv_Ratzon)\
**Post date:** [October 15, 2015, 5:10pm UTC](https://discuss.elastic.co/t/parsing-a-crappy-date-format/32263/7 "2015-10-15T17:10:25Z")

</div>

I tried it and apparently it won't parse it if it doesn't fit 100%. in your example it gives an error that says the string is malformed at "\r" - it simply reads the newline character with the date and gives a date parse failure.  
Is there maybe something wrong with the configurations at some yml file? becaus it seems odd that it won't read only the format it is searching for and hand out an error because there are more characters than it expected.

thanks !

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 15, 2015, 5:30pm UTC](https://discuss.elastic.co/t/parsing-a-crappy-date-format/32263/8 "2015-10-15T17:30:39Z")

</div>

Unlike the grok filter the date filter requires the string to match exactly. The \r character is the CR part of a Windows-style CR/LF linebreak, but that should arguably be ignored by the date filter. You should be able to use the strip option of the mutate filter to remove the \r.

---

<div class="post-metadata">

**Author:** ![Aviv\_Ratzon](https://avatars.discourse-cdn.com/v4/letter/a/df788c/32.png) [@Aviv\_Ratzon](https://discuss.elastic.co/u/Aviv_Ratzon)\
**Post date:** [October 15, 2015, 7:00pm UTC](https://discuss.elastic.co/t/parsing-a-crappy-date-format/32263/9 "2015-10-15T19:00:00Z")

</div>

Ahhh I see... Okay this is much clearer now.  
So one last question and sorry if its dumb: I managed to parse the date and time in the log into a field. The problem is that they are logged as two entries(or two values, I don't know how its called) e.g:

```
"logdate":["10.09.15","13:56:28:6238"]

```

How can I make them into a single string so that I could use the date filter on it? I've looked quite a bit and can't seem to find a way to merge them.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 15, 2015, 7:02pm UTC](https://discuss.elastic.co/t/parsing-a-crappy-date-format/32263/10 "2015-10-15T19:02:17Z")

</div>

Untested but should at least give you ideas:

```
mutate {
  replace => ["logdate", "%{[logdate][0]} %{[logdate][1]}"]
}
```

---

<div class="post-metadata">

**Author:** ![Aviv\_Ratzon](https://avatars.discourse-cdn.com/v4/letter/a/df788c/32.png) [@Aviv\_Ratzon](https://discuss.elastic.co/u/Aviv_Ratzon)\
**Post date:** [October 15, 2015, 7:03pm UTC](https://discuss.elastic.co/t/parsing-a-crappy-date-format/32263/11 "2015-10-15T19:03:34Z")

</div>

Ah good, I didn't know I could access the entries this way.  
Thank you very much for all the great help and quick replies!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:26am UTC](https://discuss.elastic.co/t/parsing-a-crappy-date-format/32263/12 "2017-07-06T05:26:23Z")

</div>


