# Problem with date filter

**URL:** <https://discuss.elastic.co/t/problem-with-date-filter/304261>\
**Category:** Logstash\
**Created:** [May 9, 2022, 2:07pm UTC](https://discuss.elastic.co/t/problem-with-date-filter/304261 "2022-05-09T14:07:14Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Thuunder7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thuunder7/32/97482_2.png) [@Thuunder7](https://discuss.elastic.co/u/Thuunder7)\
**Post date:** [May 9, 2022, 2:07pm UTC](https://discuss.elastic.co/t/problem-with-date-filter/304261/1 "2022-05-09T14:07:14Z")

</div>

Hello,  
I have been trying to use the date filter plugin but without success. I am trying to parse a field and target it into @timestamp field.

My message field contains a date string like the following:

**2022-05-09 09:19:07,900 [xJQsL/r76U:396] DEBUG**

I am creating two new fields: modb.date and modb.ms. The field mobd.date and modb.ms are corretly parsed , and respectively get the values 2022-05-09 09:19:07 and 900. Then i concatenate both to create a new field called modb.time with the format 2022-05-09 09:19:07.900.

The problem happens when i try to use the date filter on this modb.time field. When the documents get indexed i can see on the field tags, "\_dateparsefailure". I have tried to parse with multiple formats but without success.

I can only parse the modb.time value when i remove the miliseconds (.SSS) in the parsing format.

```auto
filter {
    dissect {
        mapping => { "message" => "%{[modb][date]},%{[modb][ms]}[" }
    }

    mutate {
        add_field => { "[modb][time]" => "%{[modb][date]}.%{[modb][ms]}" }
    }

    date {
        #match => ["timestamp", "MM/d/yyyy h:mm:ss a"]
        match => ["[modb][time]", "yyyy-MM-dd hh:mm:ss.SSS" ]
        target => ["@timestamp"]
    }
}

```

Do you have any ideias why is this happening?  
Regards

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [May 9, 2022, 2:25pm UTC](https://discuss.elastic.co/t/problem-with-date-filter/304261/2 "2022-05-09T14:25:02Z")

</div>

`2022-05-09 09:19:07,900 [xJQsL/r76U:396] DEBUG`

There is a space after the ms in timestamp and the `[` that isn't account for in the Grok pattern.

Try this. `%{[modb][date]},%{[modb][ms]} [`

---

<div class="post-metadata">

**Author:** ![Thuunder7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thuunder7/32/97482_2.png) [@Thuunder7](https://discuss.elastic.co/u/Thuunder7)\
**Post date:** [May 9, 2022, 2:49pm UTC](https://discuss.elastic.co/t/problem-with-date-filter/304261/3 "2022-05-09T14:49:31Z")

</div>

Nice finding 😅 It was resolved with your solution.  
Thank you!

---

<div class="post-metadata">

**Author:** ![Thuunder7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thuunder7/32/97482_2.png) [@Thuunder7](https://discuss.elastic.co/u/Thuunder7)\
**Post date:** [May 10, 2022, 3:20pm UTC](https://discuss.elastic.co/t/problem-with-date-filter/304261/4 "2022-05-10T15:20:04Z")

</div>

Seems like i am having issues again with the date filter. Yesterday was working fine, but today is not working anymore...

Field to be parsed by date filter: `2022-05-10 15:11:28.209`

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/8/88801f485c664633988f42e1c1010a0a645947a3.png)

Filter used:

```auto
date {
        match => ["[modb][time]", "yyyy-MM-dd hh:mm:ss.SSS" ]
        target => ["@timestamp"]
    }

```

I didn't touch the date filter since it was working.  
Do you see anything that i am not seeing?

Regards

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [May 10, 2022, 4:00pm UTC](https://discuss.elastic.co/t/problem-with-date-filter/304261/5 "2022-05-10T16:00:10Z")

</div>

Try big `H`'s for the hour. [Documentation](https://www.joda.org/joda-time/key_format.html).

```auto
match => ["[modb][time]", "yyyy-MM-dd HH:mm:ss.SSS" ]

```

---

<div class="post-metadata">

**Author:** ![Thuunder7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thuunder7/32/97482_2.png) [@Thuunder7](https://discuss.elastic.co/u/Thuunder7)\
**Post date:** [May 13, 2022, 8:29am UTC](https://discuss.elastic.co/t/problem-with-date-filter/304261/6 "2022-05-13T08:29:08Z")

</div>

Thanks Aaron, it is working. I was confused since with the previous pattern worked and suddenly stopped.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 10, 2022, 8:29am UTC](https://discuss.elastic.co/t/problem-with-date-filter/304261/7 "2022-06-10T08:29:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
