# Parsing timestamp

**URL:** <https://discuss.elastic.co/t/parsing-timestamp/305708>\
**Category:** Logstash\
**Created:** [May 26, 2022, 12:25pm UTC](https://discuss.elastic.co/t/parsing-timestamp/305708 "2022-05-26T12:25:29Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![alon\_carmelly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alon_carmelly/32/118670_2.png) [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Post date:** [May 26, 2022, 12:25pm UTC](https://discuss.elastic.co/t/parsing-timestamp/305708/1 "2022-05-26T12:25:30Z")

</div>

trying to parse with this 🙂

```auto
if "one-sync" in [tags] and "heart-sync" in [tags] and "edemand" in [tags] and "events" in [tags] {
    date {
        match => ["timestamp", "yyyy-MM-dd'T'HH:mm:ss'.'SSS'Z'"]
        timezone => "GMT"
        target => "@timestamp"}

```

log looks like this:  
{"level":"debug","message":"Received resonse 4611 ","timestamp":"2022-05-26T12:06:11.079Z"}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 26, 2022, 4:52pm UTC](https://discuss.elastic.co/t/parsing-timestamp/305708/2 "2022-05-26T16:52:14Z")

</div>

What is the question?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 27, 2022, 3:12am UTC](https://discuss.elastic.co/t/parsing-timestamp/305708/3 "2022-05-27T03:12:48Z")

</div>

Since you already have in the valid time format, use:

```auto
      date {
        match => ["timestamp", "ISO8601"]
      }

```

---

<div class="post-metadata">

**Author:** ![alon\_carmelly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alon_carmelly/32/118670_2.png) [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Post date:** [May 27, 2022, 7:55pm UTC](https://discuss.elastic.co/t/parsing-timestamp/305708/4 "2022-05-27T19:55:40Z")

</div>

Well, it doesn't seem to parse the date. It doesn't throw an error just doesn't work,  
Perhaps the conditionig syntext is off ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 27, 2022, 8:20pm UTC](https://discuss.elastic.co/t/parsing-timestamp/305708/5 "2022-05-27T20:20:56Z")

</div>

If there is no \_dateparsefailure tag then either the source field does not exist or the conditional is preventing the date filter from processing the event.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 28, 2022, 1:10pm UTC](https://discuss.elastic.co/t/parsing-timestamp/305708/6 "2022-05-28T13:10:38Z")

</div>

If there is no error, that means it's fine now on LS side, recreate index pattern because time was string before, now is date.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 25, 2022, 1:11pm UTC](https://discuss.elastic.co/t/parsing-timestamp/305708/7 "2022-06-25T13:11:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
