# Unable to parse datetime from log message

**URL:** <https://discuss.elastic.co/t/unable-to-parse-datetime-from-log-message/165490>\
**Category:** Logstash\
**Created:** [January 23, 2019, 10:07pm UTC](https://discuss.elastic.co/t/unable-to-parse-datetime-from-log-message/165490 "2019-01-23T22:07:05Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![cganesan](https://avatars.discourse-cdn.com/v4/letter/c/b9e5f3/32.png) [@cganesan](https://discuss.elastic.co/u/cganesan)\
**Post date:** [January 23, 2019, 10:07pm UTC](https://discuss.elastic.co/t/unable-to-parse-datetime-from-log-message/165490/1 "2019-01-23T22:07:05Z")

</div>

I'm unable to extract the datetime field from the log streamed from filebeat to elsaticsearch via logstash. I'm using date filter to extract the timestamp from the log message and set it to @timestamp. Since I already spent few hours without any luck I'm reaching out to for help.

Thanks in advance.

Here's the info:

**logstash output:**

[0] "beats\_input\_codec\_plain\_applied",  
[1] " **\_dateparsefailure**"  
],  
" **message**" =\> "[2019-01-08 01:49:04] [INFO] [test] Test log message ",

**Date filter:**  
filter {  
date {  
match =\> ["message", "YYYY-mm-dd HH:mm:ss"]  
target =\> "@timestamp"  
}  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 23, 2019, 10:33pm UTC](https://discuss.elastic.co/t/unable-to-parse-datetime-from-log-message/165490/2 "2019-01-23T22:33:37Z")

</div>

The pattern in the date filter has to match the whole of the field that you pass to it. You can use dissect to extract the timestamp from the message. Also, note than months are MM, not mm.

Try

```
    dissect { mapping => { "message" => "[%{ts} %{+ts}]%{}" } }
    date { match => ["ts", "YYYY-MM-dd HH:mm:ss"] }
```

---

<div class="post-metadata">

**Author:** ![cganesan](https://avatars.discourse-cdn.com/v4/letter/c/b9e5f3/32.png) [@cganesan](https://discuss.elastic.co/u/cganesan)\
**Post date:** [January 24, 2019, 2:32pm UTC](https://discuss.elastic.co/t/unable-to-parse-datetime-from-log-message/165490/3 "2019-01-24T14:32:23Z")

</div>

Thanks, your solution worked. However, I don't see the log statements with matched timestamp entries from Kibana UI. UI is only showing unmatched entries. I do see the updated @timestamp field in console output. I'm using following logstash filter. Pardon my errors as I'm going thru the learning process.

```
filter {
    dissect { mapping => { "message" => "[%{ts} %{+ts}]%{}" } }
    date {
      match => ["ts", "YYYY-MM-dd HH:mm:ss"]
      target => "@timestamp"
    }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 24, 2019, 3:02pm UTC](https://discuss.elastic.co/t/unable-to-parse-datetime-from-log-message/165490/4 "2019-01-24T15:02:19Z")

</div>

If the date filter does not match then @timestamp on the events will be current and they will show up in a "Last 15 minutes" view. If the date filter does match then you may need a "Last month" view to see them.

---

<div class="post-metadata">

**Author:** ![cganesan](https://avatars.discourse-cdn.com/v4/letter/c/b9e5f3/32.png) [@cganesan](https://discuss.elastic.co/u/cganesan)\
**Post date:** [January 24, 2019, 3:24pm UTC](https://discuss.elastic.co/t/unable-to-parse-datetime-from-log-message/165490/5 "2019-01-24T15:24:16Z")

</div>

Works like a charm. Thank You!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 21, 2019, 3:24pm UTC](https://discuss.elastic.co/t/unable-to-parse-datetime-from-log-message/165490/6 "2019-02-21T15:24:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
