# Strange data type error after upgraded ELK to 8.0 - "failed to parse date field \[...\]"

**URL:** <https://discuss.elastic.co/t/strange-data-type-error-after-upgraded-elk-to-8-0-failed-to-parse-date-field/299031>\
**Category:** Elasticsearch\
**Created:** [March 8, 2022, 3:07am UTC](https://discuss.elastic.co/t/strange-data-type-error-after-upgraded-elk-to-8-0-failed-to-parse-date-field/299031 "2022-03-08T03:07:12Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![pinehk](https://avatars.discourse-cdn.com/v4/letter/p/e0b2c6/32.png) [@pinehk](https://discuss.elastic.co/u/pinehk)\
**Post date:** [March 8, 2022, 3:07am UTC](https://discuss.elastic.co/t/strange-data-type-error-after-upgraded-elk-to-8-0-failed-to-parse-date-field/299031/1 "2022-03-08T03:07:12Z")

</div>

Upgraded ELK from 7.15 to 8.0, basic configurations are unchanged. But in 8.0, a CSV filter suddenly broke at unit test, failing to process a line that worked perfectly fine in 7.

The error is

```auto
"caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"failed to parse date field [FOB] with format [strict_date_optional_time||epoch_millis]", "caused_by"=>{"type"=>"date_time_parse_exception", "reason"=>"Failed to parse with all enclosed parsers"}}

```

The field that caused this is definitely not a datetime (a string "FOB"), and it is in the first line in the CSV file. Compared the data type in mappings created by logstash, it is in fact a date in 8.0, while it is text in 7.15.

Mapping in 7.15:

```auto
        "seg22": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        },

```

Mapping in 8:

```auto
      "seg22": {
        "type": "date"
      },

```

The csv configuration in logstash is a very simple one with nothing fancy, and nothing is changed during the upgrade. And the data file is also the same for the unit test in both ELK versions.

```auto
    csv {
      separator => "|"
      skip_header => "true"
      columns => ["seg1","seg2","seg3",...]
    }

```

Any help will be much appreciated.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2022, 3:07am UTC](https://discuss.elastic.co/t/strange-data-type-error-after-upgraded-elk-to-8-0-failed-to-parse-date-field/299031/2 "2022-04-05T03:07:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
