# Parsing date in logstsh

**URL:** <https://discuss.elastic.co/t/parsing-date-in-logstsh/305118>\
**Category:** Logstash\
**Created:** [May 19, 2022, 3:11am UTC](https://discuss.elastic.co/t/parsing-date-in-logstsh/305118 "2022-05-19T03:11:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jaikunwar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaikunwar/32/72788_2.png) [@jaikunwar](https://discuss.elastic.co/u/jaikunwar)\
**Post date:** [May 19, 2022, 3:11am UTC](https://discuss.elastic.co/t/parsing-date-in-logstsh/305118/1 "2022-05-19T03:11:31Z")

</div>

Hi team,  
I havee csv file with following data:  
name,age,gender,country,logtime  
John,34,male,China,2019-05-12 08:10  
Basil,43,male,Taiwan,2020-05-13 8:10  
Bella,25,female,USA,2018-05-14 8:10  
I am using date parser as:  
date {  
match =\> ["logtime", "YYYY-MM-dd HH:mm"]  
target =\> "@timestamp"  
timezone =\> "Canada/Eastern"  
}  
but it fails to do date parsing.  
When I remove HH:mm from match and remove time from csv it works.  
How can i match data like : Bella,25,female,USA,2018-05-14 8:10:02

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 19, 2022, 4:20am UTC](https://discuss.elastic.co/t/parsing-date-in-logstsh/305118/2 "2022-05-19T04:20:54Z")

</div>

You have two format: 2018-05-14 8:10 and 2018-05-14 8:10:02.

```auto
	 date {
      match => ["logtime", "YYYY-MM-dd HH:mm", "YYYY-MM-dd HH:mm:ss"]
      target => "@timestamp"
      timezone => "Canada/Eastern"
	 }

```

---

<div class="post-metadata">

**Author:** ![jaikunwar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaikunwar/32/72788_2.png) [@jaikunwar](https://discuss.elastic.co/u/jaikunwar)\
**Post date:** [May 19, 2022, 9:32am UTC](https://discuss.elastic.co/t/parsing-date-in-logstsh/305118/3 "2022-05-19T09:32:15Z")

</div>

I have data with without 'second' part like below:  
name,age,gender,country,logtime  
John,34,male,China,2019-05-12 08:10  
date {  
match =\> ["logtime", "YYYY-MM-dd HH:mm"]  
target =\> "@timestamp"  
timezone =\> "Canada/Eastern"  
}  
But above still fails

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 19, 2022, 7:40pm UTC](https://discuss.elastic.co/t/parsing-date-in-logstsh/305118/4 "2022-05-19T19:40:39Z")

</div>

This code is working fine:

```auto

	 mutate {
	   add_field => { "logtime" => "2018-05-14 8:10" }
	 }
	 
	 date {
      match => ["logtime", "YYYY-MM-dd H:mm"]
      target => "@timestamp"
      timezone => "Canada/Eastern"

	 }

```

![date-form](https://us1.discourse-cdn.com/elastic/original/3X/d/7/d74c51211f566c426caf4a7bcaed6e8930751bff.png)  
You can also try HH if you have 2 digits in hours and try different zone: America/Toronto.  
match =\> ["logtime", "YYYY-MM-dd HH:mm"]  
If still is not working use ruby debugger to see values.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 16, 2022, 7:40pm UTC](https://discuss.elastic.co/t/parsing-date-in-logstsh/305118/5 "2022-06-16T19:40:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
