# Parsing date for @timestamp

**URL:** <https://discuss.elastic.co/t/parsing-date-for-timestamp/219873>\
**Category:** Logstash\
**Created:** [February 18, 2020, 11:29pm UTC](https://discuss.elastic.co/t/parsing-date-for-timestamp/219873 "2020-02-18T23:29:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![AndyGarcia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andygarcia/32/62315_2.png) [@AndyGarcia](https://discuss.elastic.co/u/AndyGarcia)\
**Post date:** [February 18, 2020, 11:29pm UTC](https://discuss.elastic.co/t/parsing-date-for-timestamp/219873/1 "2020-02-18T23:29:02Z")

</div>

I have a timestamp in my CSV file that's in this format: 3/3/2013 21:53

However, sometimes the format will change to:  
3/4/2013 1:05

When I use this configuration file, it makes the timestamp the time I inject the data to logstash. I've spent all day trying to figure this out, can any body can point me in the right direction?

> input {  
> file {  
> path =\> "/usr/share/logstash/bin/marx-geo.csv"  
> start\_position =\> "beginning"  
> sincedb\_path =\> "/dev/null"  
> codec =\> plain {  
> charset =\> "ISO-8859-1"  
> }  
> }  
> }  
> filter {  
> date {  
> match =\> ["DateTime","M/dd/yyyy HH:mm", "M/d/yyyy H:mm"]  
> target =\> "@timestamp"  
> }  
> csv {  
> separator =\> ","  
> columns =\>["DateTime","Host","Src","Proto","Type","Spt","Dpt","SrcStr","CC","Country","Locale","LocaleBB","$
> 
> }
> 
> }
> 
> output {  
> elasticsearch {  
> hosts =\> "[http://192.168.30.11:9200](http://192.168.30.11:9200)"  
> index =\> "geo023"  
> }  
> }

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 19, 2020, 12:52am UTC](https://discuss.elastic.co/t/parsing-date-for-timestamp/219873/2 "2020-02-19T00:52:10Z")

</div>

First, the date filter that parses the [DateTime] filter has to come after the csv filter that creates it.

Secondly, in many cases a single character in a date filter will match both one- and two-digit fields, so you may well be able to remove the "M/dd/yyyy HH:mm" and just match against "M/d/yyyy H:mm". (You will need the mm to match 05.)

---

<div class="post-metadata">

**Author:** ![AndyGarcia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andygarcia/32/62315_2.png) [@AndyGarcia](https://discuss.elastic.co/u/AndyGarcia)\
**Post date:** [February 19, 2020, 1:44am UTC](https://discuss.elastic.co/t/parsing-date-for-timestamp/219873/3 "2020-02-19T01:44:14Z")

</div>

Thank you so much it works!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 18, 2020, 1:44am UTC](https://discuss.elastic.co/t/parsing-date-for-timestamp/219873/4 "2020-03-18T01:44:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
