# Target month name to @timestamp

**URL:** <https://discuss.elastic.co/t/target-month-name-to-timestamp/81621>\
**Category:** Logstash\
**Created:** [April 7, 2017, 2:11pm UTC](https://discuss.elastic.co/t/target-month-name-to-timestamp/81621 "2017-04-07T14:11:50Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Emilien](https://avatars.discourse-cdn.com/v4/letter/e/bcef8e/32.png) [@Emilien](https://discuss.elastic.co/u/Emilien)\
**Post date:** [April 7, 2017, 2:11pm UTC](https://discuss.elastic.co/t/target-month-name-to-timestamp/81621/1 "2017-04-07T14:11:50Z")

</div>

Hi everyone,

I'm using logstash to manage my catalina logs.  
The issue I encounter is the fact that I have to type of timestamp in my logs.

1. 2017-04-04 10:16:54,297
2. 04-Apr-2017 10:16:54.443

Here my filter configuration

> filter {  
> if [type] == "catalina"{  
> if [message] !~ /(.+)/ {  
> drop { }  
> }  
> grok {  
> match =\> [  
> "message", "%{TOMCAT\_DATESTAMP2:timestamp} %{GREEDYDATA:ActiveThread} %{LOGLEVEL:loglevel} %{USERNAME:auth}? %{USERNAME:ident}? %{USERNAME:ident}? %{IP:clientip}? %{NOTSPACE:request}? [%{GREEDYDATA:service}] %{GREEDYDATA:message}",  
> "message", "%{DATESTAMP2:timestamp} %{LOGLEVEL:loglevel} [%{NOTSPACE:service}] %{GREEDYDATA:message}"  
> ]  
> }  
> date {  
> match =\> ["timestamp" , "yyyy-MM-dd HH:mm:ss,SSS"]  
> target =\> "@timestamp"  
> }  
> }  
> }

For my fisrt type of timestamp, I don't have any issue but for the second one I always get the tag \_dateparsefailure.  
Then I'm trying to find a way to convert 04-Apr-2017 to 2017-04-04 to avoid this failure.

Any ideas?

Thank you for your help.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [April 7, 2017, 3:00pm UTC](https://discuss.elastic.co/t/target-month-name-to-timestamp/81621/2 "2017-04-07T15:00:14Z")

</div>

Cleverly, you can put two or more potential matches in your date filter by comma separating them:

```auto
date { 
  match => ["timestamp" , "yyyy-MM-dd HH:mm:ss,SSS", "dd-MMM-yyyy HH:mm:ss,SSS"]
  # target => "@timestamp" # You don't need this, it's the default behavior
  remove_field => ["timestamp"] 
  # This will automatically remove the now redundant `timestamp` field if the date filter 
  # successfully converts. It will leave the field alone if it can't convert.
}

```

The first match wins, so I would put whichever format occurs more frequently first to reduce second checks.

---

<div class="post-metadata">

**Author:** ![Emilien](https://avatars.discourse-cdn.com/v4/letter/e/bcef8e/32.png) [@Emilien](https://discuss.elastic.co/u/Emilien)\
**Post date:** [April 7, 2017, 3:12pm UTC](https://discuss.elastic.co/t/target-month-name-to-timestamp/81621/3 "2017-04-07T15:12:21Z")

</div>

I've tried it and I still have the date parse failure  
"type" =\> "catalina",  
"timestamp" =\> "04-Apr-2017 10:16:54.497",  
"tags" =\> [  
[0] "\_dateparsefailure"

Does the timestamp has a specific format?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [April 7, 2017, 3:15pm UTC](https://discuss.elastic.co/t/target-month-name-to-timestamp/81621/4 "2017-04-07T15:15:01Z")

</div>

My bad! It's a cut and paste error on my part. The second timestamp has a decimal, not a comma, separating the milliseconds. Try this:

```auto
date { 
  match => ["timestamp" , "yyyy-MM-dd HH:mm:ss,SSS", "dd-MMM-yyyy HH:mm:ss.SSS"]
  # target => "@timestamp" # You don't need this, it's the default behavior
  remove_field => ["timestamp"] 
  # This will automatically remove the now redundant `timestamp` field if the date filter 
  # successfully converts. It will leave the field alone if it can't convert.
}

```

(I fixed the decimal).

---

<div class="post-metadata">

**Author:** ![Emilien](https://avatars.discourse-cdn.com/v4/letter/e/bcef8e/32.png) [@Emilien](https://discuss.elastic.co/u/Emilien)\
**Post date:** [April 7, 2017, 3:30pm UTC](https://discuss.elastic.co/t/target-month-name-to-timestamp/81621/5 "2017-04-07T15:30:22Z")

</div>

Thanks a lot Aaron you fixed my problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 5, 2017, 3:44pm UTC](https://discuss.elastic.co/t/target-month-name-to-timestamp/81621/6 "2017-05-05T15:44:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
