# Timestamps filter

**URL:** <https://discuss.elastic.co/t/timestamps-filter/219648>\
**Category:** Logstash\
**Created:** [February 17, 2020, 3:27pm UTC](https://discuss.elastic.co/t/timestamps-filter/219648 "2020-02-17T15:27:50Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Archie\_Crawford](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/archie_crawford/32/62732_2.png) [@Archie\_Crawford](https://discuss.elastic.co/u/Archie_Crawford)\
**Post date:** [February 17, 2020, 3:27pm UTC](https://discuss.elastic.co/t/timestamps-filter/219648/1 "2020-02-17T15:27:50Z")

</div>

I cant get the "Time" field to match the message log

filter {  
mutate { replace =\> { "type" =\> "logs" } }  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:timestamp}%{DATA}%{YEAR}]%{DATA}%{SYSLOG5424SD:Alert}%{DATA}%{SYSLOG5424SD:Pid}%{DATA}%{IPV4:clientip}:%{POSINT:Port}]%{GREEDYDATA:Message}" }  
}  
grok {  
#patterns\_dir =\> ["/etc/logstash/patterns"]  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:timestamp}%{DATA}%{YEAR}]%{GREEDYDATA:Message}" }  
add\_field =\> { "subType" =\> "Common\_ICS" }  
}  
grok {  
match =\> { "message" =\> "%{IPV4:clientip}\s\*-\s-\s[%{HTTPDATE:timestamp}%{GREEDYDATA:Message}" }  
}  
date {  
match =\> ["timestamp" , "MMM d yyy HH:mm:ss", "MMM dd yyyy HH:mm:ss", "ISO8601", "ddd MMM dd HH:mm:ss yyyy"]  
add\_field =\> { "Status" =\> "Matched"}  
remove\_field =\> ["timestamp"]  
}

```
geoip {
    source => "clientip"
 }

```

}  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/5/b553114713e19480fd7affd99f625f10b3b720b8.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 17, 2020, 4:30pm UTC](https://discuss.elastic.co/t/timestamps-filter/219648/2 "2020-02-17T16:30:48Z")

</div>

Your timestamp field is "MMM dd HH:mm:ss" with no year.

---

<div class="post-metadata">

**Author:** ![Archie\_Crawford](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/archie_crawford/32/62732_2.png) [@Archie\_Crawford](https://discuss.elastic.co/u/Archie_Crawford)\
**Post date:** [February 17, 2020, 6:09pm UTC](https://discuss.elastic.co/t/timestamps-filter/219648/3 "2020-02-17T18:09:20Z")

</div>

> [@Archie\_Crawford](#):
>
> ddd MMM dd HH:mm:ss yyyy"

I dont get what your saying

---

<div class="post-metadata">

**Author:** ![chandu5565](https://avatars.discourse-cdn.com/v4/letter/c/c57346/32.png) [@chandu5565](https://discuss.elastic.co/u/chandu5565)\
**Post date:** [February 17, 2020, 6:36pm UTC](https://discuss.elastic.co/t/timestamps-filter/219648/4 "2020-02-17T18:36:29Z")

</div>

This should work

"EEE MMM dd HH:mm:ss yyyy"

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 17, 2020, 8:07pm UTC](https://discuss.elastic.co/t/timestamps-filter/219648/5 "2020-02-17T20:07:48Z")

</div>

Look at the second column of your screenshot. The timestamp field has the value "Feb 17 10:25:36", with no year.

---

<div class="post-metadata">

**Author:** ![Archie\_Crawford](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/archie_crawford/32/62732_2.png) [@Archie\_Crawford](https://discuss.elastic.co/u/Archie_Crawford)\
**Post date:** [February 17, 2020, 9:00pm UTC](https://discuss.elastic.co/t/timestamps-filter/219648/6 "2020-02-17T21:00:29Z")

</div>

Oh I see what your saying.. I really dont need that field Im trying to change the "Time" field on the far left ... is that possible ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 17, 2020, 9:51pm UTC](https://discuss.elastic.co/t/timestamps-filter/219648/7 "2020-02-17T21:51:44Z")

</div>

Well, firstly, do not use SYSLOGTIMESTAMP, since that discards the year, and if there is no year then a logstash date filter will guess, and I can guarantee that sometimes it will guess incorrectly. I would dissect it

```
dissect { mapping => { "message" => "%{} %{[@metadata][timestamp]} %{+[@metadata][timestamp]} %{+[@metadata][timestamp]} %{+[@metadata] [timestamp]} %{restOfLine}" } }
date { match => ["[@metadata][timestamp]", "MMM d HH:mm:ss yyyy" ] }

```

will get you

```
"@timestamp" => 2020-02-17T15:25:56.000Z,

```

You could use the target option on the date filter to set [Time] instead.

---

<div class="post-metadata">

**Author:** ![Archie\_Crawford](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/archie_crawford/32/62732_2.png) [@Archie\_Crawford](https://discuss.elastic.co/u/Archie_Crawford)\
**Post date:** [February 19, 2020, 8:48pm UTC](https://discuss.elastic.co/t/timestamps-filter/219648/8 "2020-02-19T20:48:03Z")

</div>

> [@chandu5565](#):
>
> EEE MMM dd HH:mm:ss yyyy

Ok thanks I will try this

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 18, 2020, 8:48pm UTC](https://discuss.elastic.co/t/timestamps-filter/219648/9 "2020-03-18T20:48:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
