# String to date type

**URL:** <https://discuss.elastic.co/t/string-to-date-type/189094>\
**Category:** Logstash\
**Created:** [July 5, 2019, 12:04pm UTC](https://discuss.elastic.co/t/string-to-date-type/189094 "2019-07-05T12:04:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![groowy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/groowy/32/45796_2.png) [@groowy](https://discuss.elastic.co/u/groowy)\
**Post date:** [July 5, 2019, 12:04pm UTC](https://discuss.elastic.co/t/string-to-date-type/189094/1 "2019-07-05T12:04:49Z")

</div>

Hi,  
I want to change my test\_log\_time field type from String to date and when I start Logstash it shows it's okay but Kibana still shows String even if I refresh the page.  
my config file:

> input {  
> beats {  
> port =\> "5044"  
> }  
> }  
> filter {  
> if "asd123" in [tags] {  
> dissect {  
> mapping =\> {  
> message =\> '%{log\_timestamp} %{+log\_timestamp} %{s-ip} %{cs-method} %{cs-uri-stem} %{cs-uri-query} %{s-port} %{cs-username} %{c-ip} %{cs-user-agent} %{cs-referer} %{response} %{sc-substatus} %{sc-win32-status} %{time-taken}'  
> }  
> }  
> }  
> else if "apache" in [tags] {  
> dissect {  
> mapping =\> {  
> message =\> '%{}"%{}":"%{clientip} %{} %{} [%{timestamp}] "%{verb} %{request} %{}" %{response} %{bytes}%{}","%{}":"%{}","%{}":"%{}"%{}'  
> }  
> }  
> }  
> else if "test" in [tags] {  
> dissect {  
> mapping =\> {  
> message =\> '%{test\_log\_time} %{+test\_log\_time} %{packet\_persec} %{diff}'  
> }  
> }  
> date {  
> match =\> ["test\_log\_time","yyyy-MM-dd HH:mm:ss"]  
> }  
> }  
> }  
> output {  
> elasticsearch {  
> hosts =\> ["localhost:9200"]  
> user =\> ----------  
> password =\> ---------  
> }  
> stdout { codec =\> rubydebug }  
> }

my example log:

> 2019-05-23 10:22:24 702281827 905

 ![test_time](https://us1.discourse-cdn.com/elastic/original/3X/4/b/4b9bc432c500b8dd859abb14a06860446efeb479.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 5, 2019, 3:27pm UTC](https://discuss.elastic.co/t/string-to-date-type/189094/2 "2019-07-05T15:27:07Z")

</div>

> [@groowy](#):
>
> date {  
> match =\> ["test\_log\_time","yyyy-MM-dd HH:mm:ss"]  
> }

This will parse the value of test\_log\_time and store the resulting Logstash::TimeStamp in @timestamp. If you want to overwrite test\_log\_time then specify the target option to the date filter.

---

<div class="post-metadata">

**Author:** ![groowy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/groowy/32/45796_2.png) [@groowy](https://discuss.elastic.co/u/groowy)\
**Post date:** [July 9, 2019, 6:49am UTC](https://discuss.elastic.co/t/string-to-date-type/189094/3 "2019-07-09T06:49:25Z")

</div>

Thank you, it works!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 6, 2019, 6:49am UTC](https://discuss.elastic.co/t/string-to-date-type/189094/4 "2019-08-06T06:49:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
