# Specifies the date format

**URL:** https://discuss.elastic.co/t/specifies-the-date-format/243178
**Category:** Logstash
**Created:** [July 30, 2020, 7:55am UTC](https://discuss.elastic.co/t/specifies-the-date-format/243178 "2020-07-30T07:55:26Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![Champion\_Xie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/champion_xie/32/71770_2.png) [@Champion\_Xie](https://discuss.elastic.co/u/Champion_Xie)
#### Post date: [July 30, 2020, 7:55am UTC](https://discuss.elastic.co/t/specifies-the-date-format/243178/1 "2020-07-30T07:55:27Z")

</div>

A timestamp that specifies the format

07/20/20 00:00:08  
match =\> ["timestamp","mm/dd/yy HH:mm:ss"]

after test result grokparsefailure

how to slove?

---

<div class="post-metadata">

### Author: ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)
#### Post date: [July 30, 2020, 10:13am UTC](https://discuss.elastic.co/t/specifies-the-date-format/243178/2 "2020-07-30T10:13:43Z")

</div>

Unfortunately I don't understand your question.  
Either you tried to use grok with a date pattern, which would be wrong as you need a date filter for that, or what you posted _is_ your date filter and that won't help us at all to solve your problem because your error occurs at a grok filter.  
Please post a more detailed response with your full data and configuration.

---

<div class="post-metadata">

### Author: ![Champion\_Xie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/champion_xie/32/71770_2.png) [@Champion\_Xie](https://discuss.elastic.co/u/Champion_Xie)
#### Post date: [July 31, 2020, 3:22am UTC](https://discuss.elastic.co/t/specifies-the-date-format/243178/3 "2020-07-31T03:22:29Z")

</div>

1st quesion:  
source filename: /home/elk/hzam\_1\_perf.log,i want only get hzam,how to slove? Is there any other way??

 ![match-mutate](https://us1.discourse-cdn.com/elastic/original/3X/d/c/dc8f9e7d3de0bc33583b82b9d001fca154029f95.png)

2nd question:  
log content:  
07/20/20 00:00:08 INFO infocity:sh(city/CityInfoBusiness.cpp:134)

The final field that i want to enter into ES

07/20/20 00:00:08 INFO infocity:sh hzam(1st can get)

07/20/20 00:00:08 the date format how to filter match

---

<div class="post-metadata">

### Author: ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)
#### Post date: [July 31, 2020, 4:21pm UTC](https://discuss.elastic.co/t/specifies-the-date-format/243178/4 "2020-07-31T16:21:03Z")

</div>

Please don't post pictures of text. That's so inconvenient ☹ Copy your configuration and insert it here as a code block (`</>` button).

1. If you use Ruby you can extract it with `event.set("reg_str", event.get("path").split("/")[-1].split("_")[0].split(".")[0])`. If you use grok, the regex is `^(.*\/|^)(?<reg_str>.*?)(_|\.|$)` (Both solutions should work even if the path contains no `/`,`_` or `.` at all)
2. The pattern for your date filter is `MM/dd/yy HH:mm:ss`

---

<div class="post-metadata">

### Author: ![Champion\_Xie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/champion_xie/32/71770_2.png) [@Champion\_Xie](https://discuss.elastic.co/u/Champion_Xie)
#### Post date: [August 5, 2020, 12:45am UTC](https://discuss.elastic.co/t/specifies-the-date-format/243178/5 "2020-08-05T00:45:58Z")

</div>

good job,thanks for yours

log content:

`07/20/20 09:28:57 INFO deletecity:bj(city/CityDeleteBusiness.cpp:55)`

source: /home/ops/log/.../abc\_4\_perf.log20200802

The end result you want

reg\_str: abc  
timestamp:  
loglevel: INFO  
action: deletecity  
city: bj

then how do i include timestamp format  
and how to removefield `infoother`

this is my config file

```
       filter {
        grok { match => { "message" => "%{DATE_US:elk_day} %{TIME:elk_time} %{LOGLEVEL:loglevel} %{GREEDYDATA:action}\:%{GREEDYDATA:city}\(%{NOTSPACE:infoother}\)"
            }
        }
 
    date {
         match => ["elk_day","MM/dd/yy Z"]
         match => ["elk_time","HH:mm:ss Z"]
         locale => "en"
         timezone => "Asia/Shanghai"
    }
    ruby {
        code => 'event.set("reg_str",event.get("source").split("/")[-1].split("-")[0].split("_")[0])'
    }
    mutate {
        remove_field => ["{infoother}"]
    }
}
```

---

<div class="post-metadata">

### Author: ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)
#### Post date: [August 5, 2020, 1:07am UTC](https://discuss.elastic.co/t/specifies-the-date-format/243178/6 "2020-08-05T01:07:36Z")

</div>

1. You can't just define the `match` option of the date filter multiple times (you should actually never have the same option multiple times in one filter). You need one string to be parsed, which means a) building a combined string of date and time before the date filter or b) not separating them in the first place, but getting them both together by using `DATESTAMP` in the grok filter.  
[https://github.com/logstash-plugins/logstash-patterns-core/blob/master/patterns/grok-patterns](https://github.com/logstash-plugins/logstash-patterns-core/blob/master/patterns/grok-patterns)
2. Why are there curly brackets in your `remove_field`? Because of these it doesn't work. The field name is `infoother`, not `{infoother}`. And if you don't want to have that field you could just leave it out in your grok pattern and end the pattern after the `(`. Then there wouldn't even be a field to delete.

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [August 5, 2020, 1:19am UTC](https://discuss.elastic.co/t/specifies-the-date-format/243178/7 "2020-08-05T01:19:11Z")

</div>

> [@Jenni](#):
>
> You can't just define the `match` option of the date filter multiple times (you should actually never have the same option multiple times in one filter).

I would say "should not" rather than "can't". Unfortunately logstash is very forgiving of this. It will merge them. It will .to\_h or .to\_a, or even .to\_s whenever it needs to do so to force the initial parse to conform to the required syntax.

In my experience it often does not merge them in the way that any reasonable person would expect.

---

<div class="post-metadata">

### Author: ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)
#### Post date: [August 5, 2020, 1:25am UTC](https://discuss.elastic.co/t/specifies-the-date-format/243178/8 "2020-08-05T01:25:26Z")

</div>

Oh thanks. Interesting to know O.o

---

<div class="post-metadata">

### Author: ![Champion\_Xie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/champion_xie/32/71770_2.png) [@Champion\_Xie](https://discuss.elastic.co/u/Champion_Xie)
#### Post date: [August 5, 2020, 3:10am UTC](https://discuss.elastic.co/t/specifies-the-date-format/243178/9 "2020-08-05T03:10:22Z")

</div>

I'm sorry, I don't know how to match the date format,could you help me ?

---

<div class="post-metadata">

### Author: ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)
#### Post date: [August 5, 2020, 7:33am UTC](https://discuss.elastic.co/t/specifies-the-date-format/243178/10 "2020-08-05T07:33:07Z")

</div>

At which point do you struggle? You could grab it as `%{DATESTAMP:elk_datetime}` and then parse it with `MM/dd/yy HH:mm:ss` like I had suggested earlier.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 2, 2020, 7:33am UTC](https://discuss.elastic.co/t/specifies-the-date-format/243178/11 "2020-09-02T07:33:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
