csv add field date parse error in logstash

Viewed 30

I'm attempting to take three columns and combine them into two new fields

Example: Job_Date 6\5\2019 Job_Start_Time 0:00 Job_End_Time 0:00

Into New Fields: timestamp_start 6/5/2019, 0:00 timestamp_end 6/5/2019, 0:00

The new fields are getting created but i'm getting the parse error below.

{
     "@timestamp" => 2019-06-22T21:08:20.370Z,
        "Warning" => 60,
           "path" => "/Users/*******/Desktop/Logstash-Files/ax_batch_performance_test_new.csv",
        "message" => "job",6/4/2019,13:45,13:45,6,120,60,15\r",
           "tags" => [
    [0] "_dateparsefailure"
],
           "host" => "host",
   "Job_Duration" => 6,
  "timestamp_end" => "6/4/2019 13:45",
 "Job_Start_Time" => "13:45",
       "Critical" => 120,
       "@version" => "1",
   "Job_End_Time" => "13:45",
       "Job_Date" => "6/4/2019",
"timestamp_start" => "6/4/2019 13:45",
         "Target" => 15,
       "Job_Name" => "job name"

I'm running logstash version 7.1.1. I have tried running the mutate command inside and outside of the date plugin.... If it matters I'm still learning.

I have successfully parsed a date format exactly like this before, but not by creating a new field and combining the data and time.

filter{
            csv {
            separator => ","
                            columns =>  ["Job_Name", "Job_Date", "Job_Start_Time", "Job_End_Time", "Job_Duration", "Critical", "Warning", "Target"]
            }
            mutate {convert => ["Job_Duration", "integer"]}
            mutate {convert => ["Critical", "integer"]}
            mutate {convert => ["Warning", "integer"]}
            mutate {convert => ["Target", "integer"]}
            mutate { add_field => {"timestamp_start" => "%{Job_Date} %{Job_Start_Time}"}}
            mutate { add_field => {"timestamp_end" => "%{Job_Date} %{Job_End_Time}"}}

                              date {
                            match => ["timestamp_start", "M/d/yyyy, HH:MM"]
                            timezone => "UTC"



}                             
                              date {
                            match => ["timestamp_end", "M/d/yyyy, HH:MM"]
                            timezone => "UTC"



}   

}

I'm expecting the date and time to be parsed and placed into @timestamp as a date.

0 Answers
Related