# Timestamp filter logstash

**URL:** <https://discuss.elastic.co/t/timestamp-filter-logstash/287199>\
**Category:** Logstash\
**Created:** [October 20, 2021, 1:37pm UTC](https://discuss.elastic.co/t/timestamp-filter-logstash/287199 "2021-10-20T13:37:08Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paveltest](https://avatars.discourse-cdn.com/v4/letter/p/c0e974/32.png) [@Paveltest](https://discuss.elastic.co/u/Paveltest)\
**Post date:** [October 20, 2021, 1:37pm UTC](https://discuss.elastic.co/t/timestamp-filter-logstash/287199/1 "2021-10-20T13:37:08Z")

</div>

I am trying to display the time from the message log, but the load time from logstash is coming out.  
The message looks like this:

> 9.17.20.121 - - [11/Oct/2021:00:00:24 +0300] 0.474 0.072 "POST /api/?AppType=1&AppVersion=4.8.7.3&AgentID=eRgdy-erfs&SectionName=GetPreviousMessagesByService HTTP/1.0" 200 20305 "-" "Mozilla/3.0 (compatible; Indy Library)" "-"  
> My filter.conf

```auto
input {
file {
        path => "/var/log/logstash/test.log"
        start_position => "beginning"
       }
}
filter {
grok {
match => { "message" => "%{IPORHOST:clientip}%{SPACE}(?:-|(%{WORD}.%{WORD}))%{SPACE}%{USER:id}%{SPACE}\[%{HTTPDATE:timestamp}\]%{SPACE}%{BASE16FLOAT:request_time}%{SPACE}%{BASE16FLOAT:request_time_upstream}%{SPACE}\"(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:http_version})?|%{DATA:rawrequest})\"%{SPACE}%{NUMBER:response}%{SPACE}(?:%{NUMBER:bytes}|-)%{SPACE}%{QS:referrer}%{SPACE}%{QS:agent}%{SPACE}%{QS:forwarder}" }
remove_field => "message"
remove_field => "host"
remove_field => "path"
remove_field => "@version"
}
grok {
match => { "message" => "%{HTTPDATE:logtimestamp}" }
}
date {
match => ["logtimestamp", "dd/MM/YYYY:HH:mm:ss Z"]
target => "logtimestamp"
remove_field => ["logtimestamp"]
locale => "en"
timezone => "UTC"
     }
mutate {
                replace => { "logtimestamp" => "%{@timestamp}" } }
}

```

![pic](https://us1.discourse-cdn.com/elastic/original/3X/e/a/eabb47c09ca38669f65acaacafe1bb836274b706.jpeg)

"logtimestamp" must have date 11 / Oct / 2021: 00: 02: 24 +0300 and type "Date".  
Help Please.

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [October 20, 2021, 1:47pm UTC](https://discuss.elastic.co/t/timestamp-filter-logstash/287199/2 "2021-10-20T13:47:23Z")

</div>

Hi,

The `date match` is not correct.  
According to the documentation :  
**MM** =\> two-digit month. zero-padded if needed. Example: 01 for January and 12 for  
**MMM** =\> abbreviated month text. Example: Jan for January. Note: The language used depends on your locale. See the locale setting for how to change the language. December

Here the format of the mounth is `Oct` so you need to use `MMM` instead of `MM`

```auto
match => ["logtimestamp", "dd/MMM/YYYY:HH:mm:ss Z"]

```

Remove the followings part of your file, you are removing the field who contains the timestamp print in your log and after you re-creat it to put it the logstash one. This make no sense.

```auto
remove_field => ["logtimestamp"]

```

```auto
mutate {
                replace => { "logtimestamp" => "%{@timestamp}" } }
}

```

You have a `_grokparsefailure` to.  
You can't do a match on the field `message` directly after delete it.  
That gives you a `_grokparsefailure` when the first filter is successful

Cad.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 20, 2021, 2:07pm UTC](https://discuss.elastic.co/t/timestamp-filter-logstash/287199/3 "2021-10-20T14:07:45Z")

</div>

If your first grok works then you delete the [message] field. That makes the second grok and the date filter no-ops, since the fields they are trying to use do not exist. Even if the date filter did work, it would remove\_field the value it had parsed, and then the mutate filter would replace it.

---

<div class="post-metadata">

**Author:** ![Paveltest](https://avatars.discourse-cdn.com/v4/letter/p/c0e974/32.png) [@Paveltest](https://discuss.elastic.co/u/Paveltest)\
**Post date:** [October 21, 2021, 6:06am UTC](https://discuss.elastic.co/t/timestamp-filter-logstash/287199/4 "2021-10-21T06:06:16Z")

</div>

Your advice helped, thanks a lot!

---

<div class="post-metadata">

**Author:** ![Paveltest](https://avatars.discourse-cdn.com/v4/letter/p/c0e974/32.png) [@Paveltest](https://discuss.elastic.co/u/Paveltest)\
**Post date:** [October 21, 2021, 6:07am UTC](https://discuss.elastic.co/t/timestamp-filter-logstash/287199/5 "2021-10-21T06:07:10Z")

</div>

Your hint helped me understand my mistake, thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 18, 2021, 6:07am UTC](https://discuss.elastic.co/t/timestamp-filter-logstash/287199/6 "2021-11-18T06:07:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
