# "type"=\>"illegal\_argument\_exception", "reason"=\>"cannot parse empty date"} in logstash logs

**URL:** <https://discuss.elastic.co/t/type-illegal-argument-exception-reason-cannot-parse-empty-date-in-logstash-logs/314991>\
**Category:** Elasticsearch\
**Created:** [September 23, 2022, 5:48am UTC](https://discuss.elastic.co/t/type-illegal-argument-exception-reason-cannot-parse-empty-date-in-logstash-logs/314991 "2022-09-23T05:48:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![madurad](https://avatars.discourse-cdn.com/v4/letter/m/f05b48/32.png) [@madurad](https://discuss.elastic.co/u/madurad)\
**Post date:** [September 23, 2022, 5:48am UTC](https://discuss.elastic.co/t/type-illegal-argument-exception-reason-cannot-parse-empty-date-in-logstash-logs/314991/1 "2022-09-23T05:48:49Z")

</div>

Hello,

Getting an error on pushing logs to logstash to elasticseacrch,

> "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field [message] of type [date] in document with id 'NVWQaIMBa0kW\_rfG7Lb1'", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"cannot parse empty date"}}}}}

As per error, cannot parse empty date, but in the logs there is a key called "time", Any idea of this issue ?

But here are sample logs in my application servers,

> {"level":"info","message":"2022-09-23T05:30:12.474630702Z","msg":"poll started at time","time":"2022-09-23T05:30:12Z"}  
> {"level":"info","msg":"Supervisor can't run, going to sleep","tenant":"event\_aigsubscription","time":"2022-09-23T05:30:12Z"}  
> {"error":"mongo: no documents in result","level":"error","msg":"fail to find lock by criteria","time":"2022-09-23T05:30:12Z"}  
> {"error":"mongo: no documents in result","level":"error","msg":"fail to find lock by criteria while poll","time":"2022-09-23T05:30:12Z"}

Thanks.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 23, 2022, 6:04am UTC](https://discuss.elastic.co/t/type-illegal-argument-exception-reason-cannot-parse-empty-date-in-logstash-logs/314991/2 "2022-09-23T06:04:57Z")

</div>

What does your logstash config look like?

---

<div class="post-metadata">

**Author:** ![madurad](https://avatars.discourse-cdn.com/v4/letter/m/f05b48/32.png) [@madurad](https://discuss.elastic.co/u/madurad)\
**Post date:** [September 23, 2022, 7:36am UTC](https://discuss.elastic.co/t/type-illegal-argument-exception-reason-cannot-parse-empty-date-in-logstash-logs/314991/3 "2022-09-23T07:36:37Z")

</div>

Thanks for your reply,

Here is the logstash configs,

input.conf

> input {  
> beats {  
> port =\> 5000  
> host =\> "0.0.0.0"  
> client\_inactivity\_timeout =\> "1200"  
> }  
> }
> 
> input {  
> beats {  
> port =\> 5001  
> ssl =\> true  
> ssl\_certificate\_authorities =\> ["/etc/logstash/cert/circles.chained.crt"]  
> ssl\_certificate =\> "/etc/logstash/cert/circles.crt"  
> ssl\_key =\> "/etc/logstash/cert/circles.key"  
> ssl\_verify\_mode =\> "force\_peer"  
> host =\> "0.0.0.0"  
> }  
> }

output.conf

> output {  
> elasticsearch {  
> hosts =\> ["[http://10.60.1.113:9200](http://10.60.1.113:9200)","[http://10.60.1.215:9200](http://10.60.1.215:9200)","[http://10.60.3.146:9200](http://10.60.3.146:9200)"]  
> ssl =\> false  
> ssl\_certificate\_verification =\> false  
> cacert =\> "/etc/logstash/root-ca.pem"  
> user =\> "logstash"  
> password =\> "xxxxxxxxxxxxxxxxx"  
> manage\_template =\> false  
> index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
> document\_type =\> "%{[@metadata][type]}"  
> }  
> }

Logstash.yml

> pipeline.batch.size: 125  
> pipeline.batch.delay: 100  
> config.reload.automatic: false  
> dead\_letter\_queue.enable: false  
> http.host: "10.60.1.11"  
> path.logs: /var/log/logstash/  
> xpack.monitoring.enabled: true  
> xpack.monitoring.elasticsearch.username: logstash\_system  
> xpack.monitoring.elasticsearch.password: xxxxxxxxxxxxxxx  
> xpack.monitoring.elasticsearch.hosts: ["[http://10.60.1.113:9200](http://10.60.1.113:9200)","[http://10.60.1.215:9200](http://10.60.1.215:9200)","[http://10.60.3.146:9200](http://10.60.3.146:9200)"]  
> xpack.monitoring.elasticsearch.sniffing: false

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 21, 2022, 7:36am UTC](https://discuss.elastic.co/t/type-illegal-argument-exception-reason-cannot-parse-empty-date-in-logstash-logs/314991/4 "2022-10-21T07:36:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
