# Using Date plugin to parse apache2 error log datetime

**URL:** <https://discuss.elastic.co/t/using-date-plugin-to-parse-apache2-error-log-datetime/344547>\
**Category:** Logstash\
**Created:** [October 6, 2023, 6:40pm UTC](https://discuss.elastic.co/t/using-date-plugin-to-parse-apache2-error-log-datetime/344547 "2023-10-06T18:40:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![lobart78](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lobart78/32/15967_2.png) [@lobart78](https://discuss.elastic.co/u/lobart78)\
**Post date:** [October 6, 2023, 6:40pm UTC](https://discuss.elastic.co/t/using-date-plugin-to-parse-apache2-error-log-datetime/344547/1 "2023-10-06T18:40:58Z")

</div>

Hi all !

I am trying to use Logstash to parse apache2 error logs.

These logs contain a dattime in a format e.g. `Fri Oct 03 09:07:41.570 2023`. I have already successfully transfered this string into a field "eventfire" using grok pattern `%{HTTPDERROR_DATE:eventfire}`

Now, I want to set `@timestamp` field to this date using date plugin for logstash.

I have set it up like this

```auto
filter {
    date {
        match => ["eventfire", "EEE MMM dd HH:mm:ss.SSS yyyy"]
    }
}

```

the format of the date `EEE MMM dd HH:mm:ss.SSS yyyy` should be correct, because when I fire up simple Java application with `org.joda.time` and use this format, it returned the same datetime as the eventfire field above.

However, the `@timestamp` field didn't change to this date.

So, I tried to used `ruby` plugin. I ended up with following code:

```auto
date_str = event.get("eventfire")
begin
    require "date"
    date = DateTime.parse(date_str)
    event.set("@timestamp", LogStash::Timestamp.at(date.to_time.to_i))
    rescue Exception => e
        event.tag("date_parse_failure")
end

```

which works and correctly set up `@timestamp` field even if I don't set up a format for the date, the `DateTime.parse()` function correctly parse `Fri Oct 03 09:07:41.570 2023`

My question is: Why the `date` plugin didn't work ? What did I do wrong ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 6, 2023, 9:47pm UTC](https://discuss.elastic.co/t/using-date-plugin-to-parse-apache2-error-log-datetime/344547/2 "2023-10-06T21:47:28Z")

</div>

Your date filter works for me. Perhaps a [locale](https://discuss.elastic.co/t/logstash-dateparse-error/342209/2) issue?

---

<div class="post-metadata">

**Author:** ![lobart78](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lobart78/32/15967_2.png) [@lobart78](https://discuss.elastic.co/u/lobart78)\
**Post date:** [October 6, 2023, 11:00pm UTC](https://discuss.elastic.co/t/using-date-plugin-to-parse-apache2-error-log-datetime/344547/3 "2023-10-06T23:00:07Z")

</div>

Thanks, but I tried to experiment with this field, setting en, en-US, en\_US, but it didn't have any effect

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2023, 11:00pm UTC](https://discuss.elastic.co/t/using-date-plugin-to-parse-apache2-error-log-datetime/344547/4 "2023-11-03T23:00:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
