# Weird "\_dateparsefailure" issue

**URL:** <https://discuss.elastic.co/t/weird-dateparsefailure-issue/248798>\
**Category:** Logstash\
**Created:** [September 16, 2020, 9:15am UTC](https://discuss.elastic.co/t/weird-dateparsefailure-issue/248798 "2020-09-16T09:15:29Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![opellulo](https://avatars.discourse-cdn.com/v4/letter/o/e19adc/32.png) [@opellulo](https://discuss.elastic.co/u/opellulo)\
**Post date:** [September 16, 2020, 9:15am UTC](https://discuss.elastic.co/t/weird-dateparsefailure-issue/248798/1 "2020-09-16T09:15:29Z")

</div>

Hi all,  
I'm facing a really weird issue parsing the date from an access log that doesn't use standard ISO8601 format but one that looks like: **[08/Sep/2020:18:39:23 +0200]**

I captured the group with a simple grok in a field called "t\_stamp" and then applied this date filter:

> ```
> date {
> match => ["t_stamp", "dd/MMM/yyyy:hh:mm:ss Z"]
> }
> 
> ```

Problem is that this works only in about 1/3 of the logs, the rest are indexed with a \_dateparsefailure error:

 ![tstampA](https://us1.discourse-cdn.com/elastic/original/3X/5/a/5a1e8e104a669963b6a4f686756a32c23ee2a357.png)  
Log correctly parsed

 ![tstamp2A](https://us1.discourse-cdn.com/elastic/original/3X/6/4/64d2688595d11c057eca9d0cd60ad2ad0f6f3575.png)  
Log incorrectly parsed.

Since all the strings, option and fields seems the same I really cannot understand why this error. Any clue?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 16, 2020, 3:00pm UTC](https://discuss.elastic.co/t/weird-dateparsefailure-issue/248798/2 "2020-09-16T15:00:53Z")

</div>

hh is the clock hour of the half day (1 to 12). You should use HH.

---

<div class="post-metadata">

**Author:** ![opellulo](https://avatars.discourse-cdn.com/v4/letter/o/e19adc/32.png) [@opellulo](https://discuss.elastic.co/u/opellulo)\
**Post date:** [September 17, 2020, 6:44am UTC](https://discuss.elastic.co/t/weird-dateparsefailure-issue/248798/3 "2020-09-17T06:44:00Z")

</div>

Oh, You're right, now everything works as expected.  
I can't believe having fell for such a silly error.  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 15, 2020, 6:44am UTC](https://discuss.elastic.co/t/weird-dateparsefailure-issue/248798/4 "2020-10-15T06:44:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
