# Syslog output date format

**URL:** <https://discuss.elastic.co/t/syslog-output-date-format/264366>\
**Category:** Logstash\
**Created:** [February 15, 2021, 10:43pm UTC](https://discuss.elastic.co/t/syslog-output-date-format/264366 "2021-02-15T22:43:05Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 16, 2021, 12:10am UTC](https://discuss.elastic.co/t/syslog-output-date-format/264366/5 "2021-02-16T00:10:45Z")

</div>

The syslog output uses a [sprint pattern](https://github.com/logstash-plugins/logstash-output-syslog/blob/30b8f9130878595ab87dfa0fbd4b8f04b0ed7139/lib/logstash/outputs/syslog.rb#L168) of "%{+MMM dd HH:mm:ss}". The sprintf [code](https://github.com/elastic/logstash/blob/master/logstash-core/src/main/java/org/logstash/StringInterpolation.java) insert the date and time using a Joda DateTimeFormat, which in turn, I believe, uses [this function](https://github.com/elastic/logstash/blob/master/logstash-core/src/main/java/org/logstash/StringInterpolation.java). The text it inserts is locale specific. I am not aware of any locales where the short month name includes the period, but that is the only thing I can think of that cause two syslog outputs to produce different output.

---

_[View the full topic](https://discuss.elastic.co/t/syslog-output-date-format/264366)._
