# Timestamp not getting my log value using date filter logstash

**URL:** <https://discuss.elastic.co/t/timestamp-not-getting-my-log-value-using-date-filter-logstash/83993>\
**Category:** Logstash\
**Created:** [April 28, 2017, 9:50am UTC](https://discuss.elastic.co/t/timestamp-not-getting-my-log-value-using-date-filter-logstash/83993 "2017-04-28T09:50:17Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![virendra\_oswal](https://avatars.discourse-cdn.com/v4/letter/v/cdc98d/32.png) [@virendra\_oswal](https://discuss.elastic.co/u/virendra_oswal)\
**Post date:** [April 28, 2017, 9:50am UTC](https://discuss.elastic.co/t/timestamp-not-getting-my-log-value-using-date-filter-logstash/83993/1 "2017-04-28T09:50:17Z")

</div>

I have following config to fetch Http call and log date at time call was made, but @timestamp shows when log was send from FileBeat server to logstash one.

> input {  
> beats {  
> port =\> 5044  
> }  
> }

> filter {  
> if [message] !~ /Calling SMC REST API/ {  
> drop { }  
> }else {  
> grok {  
> match =\> ["message", "{URIPATHPARAM:request}"]  
> match =\> ["message", "%{DATA:timestamp}"]
> 
> }  
> date {

> ```
> match => ["timestamp", "yyyy-MM-dd HH:mm:ss.SSSS"]
> }
> 
> ```
> 
> }

> }

> output {  
> elasticsearch {  
> hosts =\> ["[http://localhost:9200/](http://localhost:9200/)"]  
> index =\> "smc\_calls-%{+YYYY.MM.dd}"  
> }

> }

Tried this too:

> input {  
> beats {  
> port =\> 5044  
> }  
> }

> filter {  
> if [message] !~ /Calling SMC REST API/ {  
> drop { }  
> }else {

> ```
> date {
> match => ["@timestamp", "YYYY-MM-dd HH:mm:ss,SSS"]
> target => "@timestamp"
> }
> 
> ```

> ```
> grok {
> match => ["message", "{URIPATHPARAM:request}"]
> 
> ```

> ```
> }
> 
> ```
> 
> }

> }

> output {  
> elasticsearch {  
> hosts =\> ["[http://localhost:9200/](http://localhost:9200/)"]

> ```
> }
> 
> ```

> stdout { codec =\> rubydebug }  
> }

This is message i get in console:

> {  
> "@timestamp" =\> 2017-04-28T11:30:38.022Z,  
> "offset" =\> 15051398,  
> "@version" =\> "1",  
> "input\_type" =\> "log",  
> "beat" =\> {  
> "hostname" =\> "host of applicaiton",  
> "name" =\> "name of host",  
> "version" =\> "5.3.1"  
> },  
> "host" =\> "name of host",  
> "source" =\> "log-file-name",  
> "message" =\> "[2017-04-24 06:43:12,592] @ INFO [jmsContainer-1]other message details",  
> "type" =\> "log",  
> "tags" =\> [  
> [0] "beats\_input\_codec\_plain\_applied",  
> [1] "\_dateparsefailure",  
> [2] "\_grokparsefailure"  
> ]  
> }

Please help

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 28, 2017, 11:26am UTC](https://discuss.elastic.co/t/timestamp-not-getting-my-log-value-using-date-filter-logstash/83993/2 "2017-04-28T11:26:07Z")

</div>

What does the `timestamp` field that you're trying to parse with the date filter look like? Does the contents of that field follow the pattern of your date filter?

---

<div class="post-metadata">

**Author:** ![virendra\_oswal](https://avatars.discourse-cdn.com/v4/letter/v/cdc98d/32.png) [@virendra\_oswal](https://discuss.elastic.co/u/virendra_oswal)\
**Post date:** [April 28, 2017, 11:28am UTC](https://discuss.elastic.co/t/timestamp-not-getting-my-log-value-using-date-filter-logstash/83993/3 "2017-04-28T11:28:39Z")

</div>

this is [2017-04-25 12:41:25,064] date format, which is start of log line which contains http url, which i have taken out.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 28, 2017, 11:46am UTC](https://discuss.elastic.co/t/timestamp-not-getting-my-log-value-using-date-filter-logstash/83993/4 "2017-04-28T11:46:26Z")

</div>

You have multiple configuration problems but I don't think it's fruitful that I start listing them. I think you're trying to do too much at a time. Start with the grok filter. Get it to extract the timestamp into a field. Verify that that works. Then add the date filter and make sure its pattern matches what the timestamp field looks like. You can use the grok constructor web site to get help constructing a grok expression that matches your input.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 26, 2017, 11:56am UTC](https://discuss.elastic.co/t/timestamp-not-getting-my-log-value-using-date-filter-logstash/83993/5 "2017-05-26T11:56:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
