# Timestamp format fails when there's a space in my timestamp field

**URL:** https://discuss.elastic.co/t/timestamp-format-fails-when-theres-a-space-in-my-timestamp-field/137211
**Category:** Elasticsearch
**Created:** [June 25, 2018, 8:16am UTC](https://discuss.elastic.co/t/timestamp-format-fails-when-theres-a-space-in-my-timestamp-field/137211 "2018-06-25T08:16:01Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Oren\_Cohen](https://avatars.discourse-cdn.com/v4/letter/o/4491bb/32.png) [@Oren\_Cohen](https://discuss.elastic.co/u/Oren_Cohen)
#### Post date: [June 25, 2018, 8:16am UTC](https://discuss.elastic.co/t/timestamp-format-fails-when-theres-a-space-in-my-timestamp-field/137211/1 "2018-06-25T08:16:01Z")

</div>

Hey,  
I've been poking around with the Kibana dev tools and created an index called orglogs and a type called log  
Here it is:  
\> POST orglogs/log

> ```
> {
> "properties": {
> "_timestamp": {
> "type": "object"
> },
> "message": {
> "type": "text",
> "fields": {
> "keyword": {
> "type": "keyword",
> "ignore_above": 256
> }
> }
> },
> "text": {
> "type": "text",
> "fields": {
> "keyword": {
> "type": "keyword",
> "ignore_above": 256
> }
> }
> },
> "timestamp": {
> "type": "date",
> "format": "yyyy-MM-dd HH:mm:ss.SSS||yyyy-MM-dd HH:mm:ss||yyyy-MM-dd HH:mm:ss.S||yyyy-MM-dd HH:mm:ss.SS||yyyy-MM-dd HH:mm:ss"
> },
> "type": {
> "type": "text",
> "fields": {
> "keyword": {
> "type": "keyword",
> "ignore_above": 256
> }
> }
> }
> }
> }
> 
> ```

Afterwards, I tried sending a POST request:

> ```
> POST orglogs/log
> {"type":"log","timestamp":"2018-05-13 14:42:46.320","message":"FOVs set to V=39.1, H=50.8"}
> 
> ```

Then, I get a parsing problem:  
\> {

> ```
> "error": {
> "root_cause": [
> {
> "type": "mapper_parsing_exception",
> "reason": "failed to parse [timestamp]"
> }
> ],
> "type": "mapper_parsing_exception",
> "reason": "failed to parse [timestamp]",
> "caused_by": {
> "type": "illegal_argument_exception",
> "reason": "Invalid format: \"2018-05-13 14:42:46.320\" is malformed at \" 14:42:46.320\""
> }
> },
> "status": 400
> }
> 
> ```

I don't understand why this happens.  
When I tried changing the format to yyyy-MM-dd'T'HH:mm:ss.SSS and adding that T in the timestamp field, it worked. But there must be a way to do it without compromising readability.  
Any help?

Thanks,  
Oren

---

<div class="post-metadata">

### Author: ![tdasch](https://avatars.discourse-cdn.com/v4/letter/t/58f4c7/32.png) [@tdasch](https://discuss.elastic.co/u/tdasch)
#### Post date: [June 25, 2018, 1:13pm UTC](https://discuss.elastic.co/t/timestamp-format-fails-when-theres-a-space-in-my-timestamp-field/137211/2 "2018-06-25T13:13:20Z")

</div>

Oren

I put the mapping in:

```
PUT orglogs
{
  "mappings": {
    "log": {
      "properties": {
        "_timestamp": {
          "type": "object"
        },
        "message": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        },
        "text": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        },
        "timestamp": {
          "type": "date",
          "format": "yyyy-MM-dd HH:mm:ss.SSS||yyyy-MM-dd HH:mm:ss||yyyy-MM-dd HH:mm:ss.S||yyyy-MM-dd HH:mm:ss.SS||yyyy-MM-dd HH:mm:ss"
        },
        "type": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        }
      }
    }
  }
}

```

I then put in my data:

```
POST orglogs/log
{
  "type":"log",
  "timestamp":"2018-05-13 14:42:46.320",
  "message":"FOVs set to V=39.1, H=50.8"
}  

```

And then searched:

```
GET orglogs/log/_search
{
  "query": {
    "match_all": {}
  }
}

```

Search results:

```
{
  "took": 45,
  "timed_out": false,
  "_shards": {
    "total": 5,
    "successful": 5,
    "skipped": 0,
    "failed": 0
  },
  "hits": {
    "total": 1,
    "max_score": 1,
    "hits": [
      {
        "_index": "orglogs",
        "_type": "log",
        "_id": "rb8ON2QBkZR8mfXFMQSD",
        "_score": 1,
        "_source": {
          "type": "log",
          "timestamp": "2018-05-13 14:42:46.320",
          "message": "FOVs set to V=39.1, H=50.8"
        }
      }
    ]
  }
}

```

I did my mapping as a put is the only difference I think.

---

<div class="post-metadata">

### Author: ![Oren\_Cohen](https://avatars.discourse-cdn.com/v4/letter/o/4491bb/32.png) [@Oren\_Cohen](https://discuss.elastic.co/u/Oren_Cohen)
#### Post date: [June 25, 2018, 3:05pm UTC](https://discuss.elastic.co/t/timestamp-format-fails-when-theres-a-space-in-my-timestamp-field/137211/3 "2018-06-25T15:05:19Z")

</div>

> [@tdasch](#):
>
> GET orglogs/log/\_search { "query": { "match\_all": {} } }

Thank you so much! I have no idea why the minor change worked, but it did all the same.  
Much appreciated!

Thanks,  
Oren

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 23, 2018, 3:09pm UTC](https://discuss.elastic.co/t/timestamp-format-fails-when-theres-a-space-in-my-timestamp-field/137211/4 "2018-07-23T15:09:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
