# Potential parsing failure of zeek.smtp.date field through the zeek's filebeat smtp pipeline

**URL:** <https://discuss.elastic.co/t/potential-parsing-failure-of-zeek-smtp-date-field-through-the-zeeks-filebeat-smtp-pipeline/288948>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 11, 2021, 5:51am UTC](https://discuss.elastic.co/t/potential-parsing-failure-of-zeek-smtp-date-field-through-the-zeeks-filebeat-smtp-pipeline/288948 "2021-11-11T05:51:00Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![eyng](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@eyng](https://discuss.elastic.co/u/eyng)\
**Post date:** [November 11, 2021, 5:51am UTC](https://discuss.elastic.co/t/potential-parsing-failure-of-zeek-smtp-date-field-through-the-zeeks-filebeat-smtp-pipeline/288948/1 "2021-11-11T05:51:00Z")

</div>

Hello,

This appears to be a known issue similar to [Filebeat Zeek and date parsing with SMTP broken](https://discuss.elastic.co/t/filebeat-zeek-and-date-parsing-with-smtp-broken/248103), but the issue still persists in filebeat-7.15.1-x86\_64.rpm module. As the SMTP Date fields format can vary depending on the implementations, defining the format of zeek.smtp.date field can potentially cause lots of errors. So I think eliminating the formats definition in the pipeline.yml file in the filebeat packages in the repository would be preferrable to many users.

Sample Date formats:

```auto
Wed, 10 Nov 2021 22:01:02 -0600 (CST)
Thu, 11 Nov 2021 13:00:01 +0900 (JST)
11 Nov 2021 13:00:20 +0900
Fri, 15 Oct 2021 06:11:22 GMT

```

filebeat package and snippet from zeek's smtp module:

```auto
filebeat-7.15.1-x86_64.rpm
/usr/share/filebeat/module/zeek/smtp/ingest/pipeline.yml
- date:
    field: zeek.smtp.date
    target_field: zeek.smtp.date
    formats:
    - EEE, d MMM yyyy HH:mm:ss Z
    if: ctx.zeek.smtp.date != null

```

Relevant pipeline:

```auto
GET /_ingest/pipeline/filebeat-7.15.1-zeek-smtp-pipeline
{
  "filebeat-7.15.1-zeek-smtp-pipeline" : {

 : snip

      {
        "date" : {
          "field" : "zeek.smtp.date",
          "target_field" : "zeek.smtp.date",
          "formats" : [
            "EEE, d MMM yyyy HH:mm:ss Z"
          ],
          "if" : "ctx.zeek.smtp.date != null"
        }
      },

```

Any guidance would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 9, 2021, 7:51am UTC](https://discuss.elastic.co/t/potential-parsing-failure-of-zeek-smtp-date-field-through-the-zeeks-filebeat-smtp-pipeline/288948/2 "2021-12-09T07:51:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
