# Problems parsing time in logstash with date filter

**URL:** <https://discuss.elastic.co/t/problems-parsing-time-in-logstash-with-date-filter/113582>\
**Category:** Logstash\
**Created:** [December 29, 2017, 12:12pm UTC](https://discuss.elastic.co/t/problems-parsing-time-in-logstash-with-date-filter/113582 "2017-12-29T12:12:31Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![anchasis](https://avatars.discourse-cdn.com/v4/letter/a/4af34b/32.png) [@anchasis](https://discuss.elastic.co/u/anchasis)\
**Post date:** [December 29, 2017, 12:12pm UTC](https://discuss.elastic.co/t/problems-parsing-time-in-logstash-with-date-filter/113582/1 "2017-12-29T12:12:31Z")

</div>

I have a problem parsing a timestamp of the format "2017-06-28T10:28:18.000Z". It should match both  
"ISO8601" and "YYYY-MM-dd'T'HH:mm:ss.SSS'Z'" but apparently it doesn't. All other formats get parsed correctly

I tried everything but it doesn't get converted to timestamp type. I use this filter:

```
date {
    match => [
        "custom_time_field",
        "YYYY-MM-dd HH:mm:ss.SSS",
        "YYYY-MM-dd HH:mm:ss.SS",
        "YYYY-MM-dd HH:mm:ss.S",
        "YYYY-MM-dd HH:mm:ss",
        "YYYY-MM-dd'T'HH:mm:ss.SSS'Z'",
        "YYYY-MM-dd'T'HH:mm:ss.SS'Z'",
        "YYYY-MM-dd'T'HH:mm:ss.S'Z'",
        "YYYY-MM-dd'T'HH:mm:ss'Z'",
        "ISO8601"
    ]
    target => 'custom_time_field_time'
}

```

I am out of idea's. Anyone that can give me a pointer would be very helpful

---

<div class="post-metadata">

**Author:** ![anchasis](https://avatars.discourse-cdn.com/v4/letter/a/4af34b/32.png) [@anchasis](https://discuss.elastic.co/u/anchasis)\
**Post date:** [December 29, 2017, 3:04pm UTC](https://discuss.elastic.co/t/problems-parsing-time-in-logstash-with-date-filter/113582/2 "2017-12-29T15:04:56Z")

</div>

Solution found,

in the filter section there was also a

convert =\> {  
...  
}

filter that tried to convert that field to date\_time type. I guess this must have caused a race condition in some cases with the date filter

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 26, 2018, 3:05pm UTC](https://discuss.elastic.co/t/problems-parsing-time-in-logstash-with-date-filter/113582/3 "2018-01-26T15:05:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
