# Problem to add new date field in filter logstash

**URL:** <https://discuss.elastic.co/t/problem-to-add-new-date-field-in-filter-logstash/338107>\
**Category:** Logstash\
**Created:** [July 11, 2023, 1:10pm UTC](https://discuss.elastic.co/t/problem-to-add-new-date-field-in-filter-logstash/338107 "2023-07-11T13:10:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![shayn](https://avatars.discourse-cdn.com/v4/letter/s/77aa72/32.png) [@shayn](https://discuss.elastic.co/u/shayn)\
**Post date:** [July 11, 2023, 1:10pm UTC](https://discuss.elastic.co/t/problem-to-add-new-date-field-in-filter-logstash/338107/1 "2023-07-11T13:10:24Z")

</div>

i have date field called case\_start\_time in format of date and time .  
i am trying to add new field called case\_day which will cut the date without the time from case\_start\_time .

case\_start\_time: 09/07/23 23:54:26

case\_day should be 09/07/23

i tried to use this logastash filter :

```auto
  filter {
        mutate {
            split => { "case_start_time" => " " }
            add_field => { "case_day" => "%{[case_start_time][0]}" }
        }

```

and got the array pattern itseld and not the content as required  
case\_day: %{[case\_start\_time][0]}

i have also tried to use ruby code

```
`ruby {code => 'event.set("case_day", event.get("case_start_time").split(" ")[0])'}`

```

and got  
Ruby exception occurred: undefined method `strftime'

also tried

```auto
date {
        match => ["case_start_time", "DD/MM/YY HH:mm:ss" ,"ISO8601"]
        target => "case_day"
        #remove_field => ["case_start_time"]
      }
 mutate {
  
    gsub => ["case_day", "^(\d{2}\/\d{2}\/\d{2}).*$", "\1"]
      }

```

and got dateparseerror  
what is the right filter that i should use ?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 11, 2023, 1:34pm UTC](https://discuss.elastic.co/t/problem-to-add-new-date-field-in-filter-logstash/338107/2 "2023-07-11T13:34:54Z")

</div>

> [@shayn](#):
>
> and got the array pattern itseld and not the content as required  
> case\_day: %{[case\_start\_time][0]}

Can you share an example of your document? Because I replicate your filter without any issues and it worked without any issues.

> [@shayn](#):
>
> `match => ["case_start_time", "DD/MM/YY HH:mm:ss" ,"ISO8601"]`

In this case you have an extra space between the date and the time.

---

<div class="post-metadata">

**Author:** ![shayn](https://avatars.discourse-cdn.com/v4/letter/s/77aa72/32.png) [@shayn](https://discuss.elastic.co/u/shayn)\
**Post date:** [July 12, 2023, 8:50am UTC](https://discuss.elastic.co/t/problem-to-add-new-date-field-in-filter-logstash/338107/3 "2023-07-12T08:50:59Z")

</div>

I've noticed that the date format i was using were wrong ..  
this is the correct date format  
`yyyy-mm-ddTHH:mm:ss.SSSZ`

i changed the match field .  
`match => ["case_start_time","yyyy-mm-dd HH:mm:ss.SSSZ"]`  
and got the same error  
i tried also to use  
`match => ["case_start_time","yyyy-mm-dd HH:mm:ss.SSSZ" , " ISO8601"]`  
but with no luck ..

this is how my document looks like :

```auto
"_index": "cust_complaints_2023.07.12",
  "_type": "_doc",
  "_id": "fHp7SIkBhU-YqjIOOT3v",
  "_version": 1,
  "_score": null,
  "_source": {
    "inbox_name": "team mail",
    "emp_name": "emp1",
    "case_id": 999999,
    "@version": "1",
    "tags": [
      "_dateparsefailure"
    ],
    "case_start_time": "2023-07-11T20:53:06.000Z",
    "customer_id": 888888,
    "catgory": "remote_control",
    "case_subject": "test test test",
    "@timestamp": "2023-07-12T05:03:02.522Z",
    "customer_code": "1.24531994",
    "case_note": "test test1 test2"
  },
  "fields": {
    "case_start_time": [
      "2023-07-11T20:53:06.000Z"
    ],
    "@timestamp": [
      "2023-07-12T05:03:02.522Z"
    ]
  },
  "sort": [
    1689108786000
  ]
}

```

---

<div class="post-metadata">

**Author:** ![Hemanth\_Gowda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hemanth_gowda/32/23886_2.png) [@Hemanth\_Gowda](https://discuss.elastic.co/u/Hemanth_Gowda)\
**Post date:** [July 13, 2023, 12:27pm UTC](https://discuss.elastic.co/t/problem-to-add-new-date-field-in-filter-logstash/338107/4 "2023-07-13T12:27:22Z")

</div>

match =\> ["case\_start\_time","yyyy-MM-dd'T'HH:mm:ss.SSSZ"]  
Please use this format and give it a try.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2023, 12:27pm UTC](https://discuss.elastic.co/t/problem-to-add-new-date-field-in-filter-logstash/338107/5 "2023-08-10T12:27:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
