# \[SOLVED\] Always see "\_dateparsefailure" in the logstash-plain.log

**URL:** <https://discuss.elastic.co/t/solved-always-see-dateparsefailure-in-the-logstash-plain-log/102488>\
**Category:** Logstash\
**Created:** [October 2, 2017, 8:49pm UTC](https://discuss.elastic.co/t/solved-always-see-dateparsefailure-in-the-logstash-plain-log/102488 "2017-10-02T20:49:41Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![praveenmak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/praveenmak/32/22708_2.png) [@praveenmak](https://discuss.elastic.co/u/praveenmak)\
**Post date:** [October 2, 2017, 8:49pm UTC](https://discuss.elastic.co/t/solved-always-see-dateparsefailure-in-the-logstash-plain-log/102488/1 "2017-10-02T20:49:41Z")

</div>

Hello folks,

Here is my script , I always see this line in the logstash-plain.log file. PLEASE HELP!

**[2017-10-02T16:43:59,750][DEBUG][logstash.filters.date] config LogStash::Filters::Date/@tag\_on\_failure = ["\_dateparsefailure"]**  
**[2017-10-02T16:43:59,766][DEBUG][org.logstash.filters.DateFilter] Date filter with format=yyyy-MM-dd HH:mm:ss,SSS, locale=en, timezone=America/New\_York built as org.logstash.filters.parser.JodaParser**  
**[2017-10-02T16:43:59,775][DEBUG][org.logstash.filters.DateFilter] Date filter with format=ISO8601, locale=en, timezone=America/New\_York built as org.logstash.filters.parser.CasualISO8601Parser**

echo "app,Server,Port,DateTime,Service,Method,BillingMethod,Version,Customer,CustomerIP,TransactionId,TotalBytes,RecCount,AuthTime,ESDLTime,MysqlTime,SybaseTime,RoxieTime,ESPTime,RequestLine  
appname\_1,server1,7541,2017-09-24 18:59:25,wsadl,BusinessSer,0,1.78,userlogin1,IP1.IP2.IP3.IP4,0,906,0,0,0,0,0,0,276,Request1" | sudo ./logstash --path.settings $HOME/bin/configs/logstash -e '

```
input
{
    stdin { }
}

```

output  
{  
stdout { codec =\> rubydebug }  
}

filter  
{  
csv  
{  
separator =\> ","  
autodetect\_column\_names =\> true  
remove\_field =\> ["message", "@version" , "command", "host" , "path"]  
convert =\>  
{  
"Port" =\> "integer"  
"RecCount" =\> "integer"  
"Version" =\> "float"  
"TotalBytes" =\> "integer"  
"ESDLTime" =\> "integer"  
"AuthTime" =\> "integer"  
"MysqlTime" =\> "integer"  
"SybaseTime" =\> "integer"  
"RoxieTime" =\> "integer"  
"ESPTime" =\> "integer"  
}  
}

```
    mutate
    {
       split => ["DateTime", " "]
       add_field =>
       {
           "tempdate" => "%{[DateTime][0]}T%{[DateTime][1]},000"
           timezone => "America/New_York"
       }
    }
    
   date
    {
        locale => "en"
        timezone => "America/New_York"
        match => ["tempdate", "yyyy-MM-dd HH:mm:ss,SSS", "ISO8601"]
        target => "@timestamp"
        remove_field => ["tempdate"]
        remove_field => ["DateTime"]
     }

```

}

'

---

<div class="post-metadata">

**Author:** ![praveenmak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/praveenmak/32/22708_2.png) [@praveenmak](https://discuss.elastic.co/u/praveenmak)\
**Post date:** [October 3, 2017, 2:52pm UTC](https://discuss.elastic.co/t/solved-always-see-dateparsefailure-in-the-logstash-plain-log/102488/2 "2017-10-03T14:52:20Z")

</div>

Experts,

Is it possible to help, kind of stuck.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 5, 2017, 8:37am UTC](https://discuss.elastic.co/t/solved-always-see-dateparsefailure-in-the-logstash-plain-log/102488/3 "2017-10-05T08:37:59Z")

</div>

Please remove `remove_field => ["tempdate"]` and show what your `stdout { codec => rubydebug }` output produces in your example case.

---

<div class="post-metadata">

**Author:** ![praveenmak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/praveenmak/32/22708_2.png) [@praveenmak](https://discuss.elastic.co/u/praveenmak)\
**Post date:** [October 5, 2017, 2:11pm UTC](https://discuss.elastic.co/t/solved-always-see-dateparsefailure-in-the-logstash-plain-log/102488/4 "2017-10-05T14:11:59Z")

</div>

Thanks for responding @magnusbaeck

I always get desired output, but like I mentioned in the logstash logs I see that message which concerns me.

{  
"app" =\> "appname\_1",  
"Server" =\> "server1",  
"Customer" =\> "userlogin1",  
"timezone" =\> "America/New\_York",  
"Port" =\> 7541,  
"BillingMethod" =\> "0",  
"SybaseTime" =\> 0,  
"Service" =\> "wsadl",  
"Method" =\> "BusinessSer",  
"AuthTime" =\> 0,  
"TransactionId" =\> "0",  
"ESPTime" =\> 276,  
"RequestLine" =\> "Request1",  
"MysqlTime" =\> 0,  
"@timestamp" =\> 2017-09-24T22:59:25.000Z,  
"Version" =\> 1.78,  
"ESDLTime" =\> 0,  
**"tempdate" =\> "2017-09-24T18:59:25.000",**  
"RecCount" =\> 0,  
"CustomerIP" =\> "IP1.IP2.IP3.IP4",  
"TotalBytes" =\> 906,  
"RoxieTime" =\> 0  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 5, 2017, 2:29pm UTC](https://discuss.elastic.co/t/solved-always-see-dateparsefailure-in-the-logstash-plain-log/102488/5 "2017-10-05T14:29:38Z")

</div>

Oh. It's just a debug-level log message. It doesn't indicate a problem.

---

<div class="post-metadata">

**Author:** ![praveenmak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/praveenmak/32/22708_2.png) [@praveenmak](https://discuss.elastic.co/u/praveenmak)\
**Post date:** [October 5, 2017, 2:44pm UTC](https://discuss.elastic.co/t/solved-always-see-dateparsefailure-in-the-logstash-plain-log/102488/6 "2017-10-05T14:44:43Z")

</div>

my concern is the \_dateparsefailure shows up in the elasticsearch/kibana.

So solution should be to just remove the field right?

remove\_field =\> ["tag\_on\_failure"]

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 5, 2017, 3:01pm UTC](https://discuss.elastic.co/t/solved-always-see-dateparsefailure-in-the-logstash-plain-log/102488/7 "2017-10-05T15:01:52Z")

</div>

It is just a debug message saying that IF it gets a parse failure then it would add that tag. But it parses the date correctly, so it does not add the tag. You can ignore the message.

---

<div class="post-metadata">

**Author:** ![praveenmak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/praveenmak/32/22708_2.png) [@praveenmak](https://discuss.elastic.co/u/praveenmak)\
**Post date:** [October 5, 2017, 3:37pm UTC](https://discuss.elastic.co/t/solved-always-see-dateparsefailure-in-the-logstash-plain-log/102488/8 "2017-10-05T15:37:25Z")

</div>

Thanks @Badger.  
I did notice the \_dateparsefailure in the Kibana output. I fixed it by doing "remove\_field =\> ["tag\_on\_failure"]"  
But anyways will close this issue.

Thanks for responding!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 2, 2017, 3:37pm UTC](https://discuss.elastic.co/t/solved-always-see-dateparsefailure-in-the-logstash-plain-log/102488/9 "2017-11-02T15:37:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
