# Syslog filter issue with timestamp

**URL:** <https://discuss.elastic.co/t/syslog-filter-issue-with-timestamp/290468>\
**Category:** Logstash\
**Created:** [November 29, 2021, 4:53pm UTC](https://discuss.elastic.co/t/syslog-filter-issue-with-timestamp/290468 "2021-11-29T16:53:44Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [December 1, 2021, 1:17pm UTC](https://discuss.elastic.co/t/syslog-filter-issue-with-timestamp/290468/2 "2021-12-01T13:17:46Z")

</div>

Hi

I think you didn't specified any format for `dateTime` in the mapping, so by default elasticsearch wait to get a date with the format `strict_date_optional_time` or `epoch_millis`.

According to you and logs, the `dateTime` contains the value `Nov 29, 2021 @ 11:37:17.627` in the logstash output and it does not match either of the two required formats.

> [@mylvestre](#):
>
> failed to parse date field [Nov 29 11:34:11] with format [strict\_date\_optional\_time||epoch\_millis]

So i think you have two possibilities.

- First is to edit the mapping in elasticsearch to specify the incomming date are in syslog date format. [example here](https://discuss.elastic.co/t/parsing-date-error-date-time-parse-exception-failed-to-parse-with-all-enclosed-parsers/260804/2)
- Or to use the [date filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html#_description_123) in logstash to make the change form syslog date to strict\_date\_optional\_time directly in logsatsh.

Cad

---

_[View the full topic](https://discuss.elastic.co/t/syslog-filter-issue-with-timestamp/290468)._
