# Timestamp parsing issue

**URL:** <https://discuss.elastic.co/t/timestamp-parsing-issue/44420>\
**Category:** Logstash\
**Created:** [March 15, 2016, 11:04am UTC](https://discuss.elastic.co/t/timestamp-parsing-issue/44420 "2016-03-15T11:04:17Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dhanushka1282](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dhanushka1282/32/56092_2.png) [@Dhanushka1282](https://discuss.elastic.co/u/Dhanushka1282)\
**Post date:** [March 15, 2016, 11:04am UTC](https://discuss.elastic.co/t/timestamp-parsing-issue/44420/1 "2016-03-15T11:04:17Z")

</div>

Hi All

I have log file as below

07/03/2016 03:54:56 07/03/2016 03:54:57 192.168. 2. 3 209.132.182. 33 203.115.80.90 TCP 50467 80 DNAT 2423

And my filter looks like below

```
   filter {

   if [type] == "syslog" {

    grok {

    patterns_dir => "/etc/logstash/patterns"

    match => { "message" => "%{DATE_EU:start_date}\s*%{TIMERED:start_time}\s%{DATE_EU:stop_date}\s*%{TIMERED:stop_time}\s*%{IPADDRS:source_address}\s*%{IPADDRS:destination_address}\s*%{IPADDRS:lb_address}\s*%{WORD:protocaol_type}\s*%{NUMBER:source_port}\s*%{NUMBER:dstination_port}\s*%{WORD:nat_type}\s*%{NUMBER:bytes}" }

    }

mutate {
    convert => { "source_address" => "string" }
    convert => { "destination_address" => "string" }
    convert => { "bytes" => "integer" }
    add_field => {"timestamp" => "%{start_date}:%{start_time}" }

    gsub => [
    "source_address", "\s*", "",
    "destination_address", "\s*", ""
    ]

    }

date {
match => ["timestamp" , "dd/MM/yyyy:HH:mm:ss"]
timezone => "Asia/Colombo"
     }

 geoip {
    source => "source_address"
    target => "source_geoip"
    database => "/etc/logstash/test/GeoLiteCity.dat"
     }

 geoip {
    source => "destination_address"
    target => "destination_geoip"
    database => "/etc/logstash/test/GeoLiteCity.dat"
      }

```

}

# Logstash output

But when i send the log files to the server it continuously get the following warning error

Failed parsing date from field {:field=\>"timestamp", :value=\>"%{start\_date}:%{start\_time}", :exception=\>"Invalid format: "%{start\_date}:%{start\_time}"", :config\_parsers=\>"dd/MM/yyyy:HH:mm:ss", :config\_locale=\>"default=en\_US", :level=\>:warn}

Can you guys please advice me to how to fix this timestamp issue , im struggling with this for couple of days

Thank in Advance

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 15, 2016, 11:53am UTC](https://discuss.elastic.co/t/timestamp-parsing-issue/44420/2 "2016-03-15T11:53:16Z")

</div>

What does the resulting event look like if you output the result of a line to stdout using the ruby debug codec?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:06am UTC](https://discuss.elastic.co/t/timestamp-parsing-issue/44420/3 "2017-07-06T05:06:56Z")

</div>


