# Parsing date format

**URL:** <https://discuss.elastic.co/t/parsing-date-format/269488>\
**Category:** Logstash\
**Created:** [April 7, 2021, 2:38pm UTC](https://discuss.elastic.co/t/parsing-date-format/269488 "2021-04-07T14:38:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tkkchan](https://avatars.discourse-cdn.com/v4/letter/t/8491ac/32.png) [@tkkchan](https://discuss.elastic.co/u/tkkchan)\
**Post date:** [April 7, 2021, 2:38pm UTC](https://discuss.elastic.co/t/parsing-date-format/269488/1 "2021-04-07T14:38:43Z")

</div>

Dear All,  
I am currently learning how to parse data with logstash and pass them to Logstash. Right now I am confused on how to parse date correctly, as you can see, I have a timestamp with the format  
`yyyy/MM/dd HH:mm:ss.SS`  
Right now I am using the following for getting the timestamp, which works(but with a minor issue)

```auto
filter {
    grok {
        match => { "message" => "%{DATESTAMP:event_time},%{NUMBER:coord1},%{NUMBER:coord2},%{NUMBER:depth},%{NUMBER:magnitude},%{WORD:magtype}" }
    }

    mutate {
        convert => ["event_time", "string"]
        }
    date {
        locale => "en"
        match => ["event_time", "yyyy/MM/dd HH:mm:ss'.'SS"]
        target => "@timestamp"
        remove_field => ["timestamp"]
        add_field => { "debug" => "timestampMatched"}
    }
}

```

What happened was that, after I parse my data with this configuration, a date like "2016/11/14" became "0016/11/14".

As we can see [here](https://github.com/elastic/logstash/blob/v1.4.0/patterns/grok-patterns), the DATESTAMP grok pattern consists of YEAR, MONTHNUM and other grok patterns. The YEAR grok pattern contains only 2 digits, which I think is the source of this problem, but I have no idea how to overcome it.

IF I didn't understand wrongly, what I need to do in the Logstash config is to extract the event\_time from the log message with grok, then use mutate to change it into a string, and extract the date time pattern with "date" . And now I think the problem is I need to take the whole date stamp including all the four digits of the Year parameter, but I am not sure how to do that. It seems like grok pattern of YEAR only comes with 2 digit.  
\*I have tried using regex in grok pattern, but it doesn't work either.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 7, 2021, 4:18pm UTC](https://discuss.elastic.co/t/parsing-date-format/269488/2 "2021-04-07T16:18:25Z")

</div>

> [@tkkchan](#):
>
> `%{DATESTAMP:event_time}`

I suggest you replace that with either `(?<event_time>[^,]+)` or `(?<event_time>[\d:/\.]+)`

---

<div class="post-metadata">

**Author:** ![tkkchan](https://avatars.discourse-cdn.com/v4/letter/t/8491ac/32.png) [@tkkchan](https://discuss.elastic.co/u/tkkchan)\
**Post date:** [April 9, 2021, 8:15am UTC](https://discuss.elastic.co/t/parsing-date-format/269488/3 "2021-04-09T08:15:46Z")

</div>

Dear Badger,  
Thank you very much for the prompt reply. It worked well.  
Cheers,  
TK

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 7, 2021, 8:16am UTC](https://discuss.elastic.co/t/parsing-date-format/269488/4 "2021-05-07T08:16:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
