# Syslog output date format

**URL:** <https://discuss.elastic.co/t/syslog-output-date-format/264366>\
**Category:** Logstash\
**Created:** [February 15, 2021, 10:43pm UTC](https://discuss.elastic.co/t/syslog-output-date-format/264366 "2021-02-15T22:43:05Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![gunlomboy](https://avatars.discourse-cdn.com/v4/letter/g/c0e974/32.png) [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Post date:** [February 15, 2021, 10:43pm UTC](https://discuss.elastic.co/t/syslog-output-date-format/264366/1 "2021-02-15T22:43:05Z")

</div>

Hi,

I am running Windows logs successfully to our SIEM using a kafka input and a logstash syslog output. The logs are parsing perfectly in the SIEM.

When running a virtually identical pipeline to poll a different topic from kafka (AWS Cloudtrail logs) and send to the SIEM using an identical output the logs won't parse due to an additional "." after the month in the syslog timestamp, for example:

\<13\>Feb. 15 22:35:33 abd1234.blah.com.au LOGSTASH-AWS[-]

Is there a known method to format the timestamp produced by the logstash-syslog-output plugin, or a field I can target with the date filter.

This seems to be non-configurable, but I'm hoping someone can tell me otherwise.

Thanks.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 15, 2021, 11:27pm UTC](https://discuss.elastic.co/t/syslog-output-date-format/264366/2 "2021-02-15T23:27:11Z")

</div>

Are you saying that the . after Feb is in the message received from kafka and it causes a problem downstream?

---

<div class="post-metadata">

**Author:** ![gunlomboy](https://avatars.discourse-cdn.com/v4/letter/g/c0e974/32.png) [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Post date:** [February 15, 2021, 11:36pm UTC](https://discuss.elastic.co/t/syslog-output-date-format/264366/3 "2021-02-15T23:36:18Z")

</div>

Hi,

No, the problem appears to be in the conversion and formatting within the logstash-syslog-output. The kafka object is as follows, and contains only timestamps. I just need the date in the syslog output to be of the form **\<13\>Feb 15 22:35:33**

```auto
{
  "@timestamp": "2021-02-11T01:07:51.125Z",
  "@version": "1",
  "cloudfront_version": "1.0",
  "cloudfront_fields": "XXXX",
  "message": "2021-02-11\t01:02:22\tPER50-C1\t1500\XXX",
  "fields": {
    "type": "cloudfront"
  },
  "s3": {
    "last_modified": "2021-02-11T01:07:23.000Z",
    "file": "2021-02-11-01.95fbae1e.gz"
  }
}

```

Any ideas would be great! Thanks.

---

<div class="post-metadata">

**Author:** ![gunlomboy](https://avatars.discourse-cdn.com/v4/letter/g/c0e974/32.png) [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Post date:** [February 15, 2021, 11:37pm UTC](https://discuss.elastic.co/t/syslog-output-date-format/264366/4 "2021-02-15T23:37:30Z")

</div>

and yes, the "." causes a parsing error in the SIEM.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 16, 2021, 12:10am UTC](https://discuss.elastic.co/t/syslog-output-date-format/264366/5 "2021-02-16T00:10:45Z")

</div>

The syslog output uses a [sprint pattern](https://github.com/logstash-plugins/logstash-output-syslog/blob/30b8f9130878595ab87dfa0fbd4b8f04b0ed7139/lib/logstash/outputs/syslog.rb#L168) of "%{+MMM dd HH:mm:ss}". The sprintf [code](https://github.com/elastic/logstash/blob/master/logstash-core/src/main/java/org/logstash/StringInterpolation.java) insert the date and time using a Joda DateTimeFormat, which in turn, I believe, uses [this function](https://github.com/elastic/logstash/blob/master/logstash-core/src/main/java/org/logstash/StringInterpolation.java). The text it inserts is locale specific. I am not aware of any locales where the short month name includes the period, but that is the only thing I can think of that cause two syslog outputs to produce different output.

---

<div class="post-metadata">

**Author:** ![gunlomboy](https://avatars.discourse-cdn.com/v4/letter/g/c0e974/32.png) [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Post date:** [February 16, 2021, 1:03am UTC](https://discuss.elastic.co/t/syslog-output-date-format/264366/6 "2021-02-16T01:03:49Z")

</div>

Many thanks for your time and help. This seems to be related to a known JDK bug for Australian locales:

[https://bugs.openjdk.java.net/browse/JDK-8208487](https://bugs.openjdk.java.net/browse/JDK-8208487)

Frustrating!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 16, 2021, 2:54am UTC](https://discuss.elastic.co/t/syslog-output-date-format/264366/7 "2021-02-16T02:54:29Z")

</div>

OK, so according to the bug you link to you might have a workaround by editing jvm.options. You may be able to upgrade out of it, or you may be able to change JVM providers. Also, you could consider running your JVM with another locale setting instead of en\_AU, maybe en\_GB or en\_US. Or let us never forget ... en\_CA. Lastly, you could route the syslog output to another pipeline that I think could use a tcp input,

```
 filter { mutate { gsub => ["message", "^(<\d+>\w{3})\.", "\1"] } }

```

(or something like that), and then another tcp output. You might have issue with line endings that would require you to mess with message options or codec format options on the inputs/outputs.

---

<div class="post-metadata">

**Author:** ![gunlomboy](https://avatars.discourse-cdn.com/v4/letter/g/c0e974/32.png) [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Post date:** [February 16, 2021, 3:38am UTC](https://discuss.elastic.co/t/syslog-output-date-format/264366/8 "2021-02-16T03:38:39Z")

</div>

Thanks.

Trying to upgrade out of it, but have also considered pipeline-to-pipeline to run a gsub ... might be expensine though 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 16, 2021, 3:39am UTC](https://discuss.elastic.co/t/syslog-output-date-format/264366/9 "2021-03-16T03:39:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
