Failed to parse date field [@timestamp]: unable to parse date when timezone offset present but no timezone configured
0 reputation · 09 Dec 2023, 07:35 UTC
0 reputation · 09 Dec 2023, 07:35 UTC
Goal: Determine whether Elastic Beats should automatically interpret timezone offsets embedded in log timestamps when no explicit timezone setting is provided in the input configuration.
Constraints: The behavior must be consistent across Filebeat and Metricbeat modules, avoid introducing timestamp drift across daylight‑saving transitions, and remain compatible with existing configurations that rely on UTC fallback.
Questions:
29275 reputation · 09 Dec 2023, 16:39 UTC
By default, Elastic Beats (Filebeat, Metricbeat, etc.) do **not** treat an embedded timezone offset as the event’s timezone. If the input configuration does not specify a timezone, Beats fall back to UTC and ignore any offset characters in the timestamp string.
timestamp field (or the default RFC3339/Nano) must contain a zone pattern (Z, Z07:00, -07:00, etc.) for the offset to be recognized.ignore_older and skip_on_error settings, but the event’s @timestamp is set to the Beat’s internal clock (UTC) unless a timezone option is explicitly set.2006-01-02T15:04:05.000-07:00).timestamp field to a layout that contains a zone pattern, for example:filebeat.inputs:
- type: log
paths: ["/var/log/app/*.log"]
timestamp:
format: "2006-01-02T15:04:05.000-07:00"
timezone option under the input:filebeat.inputs:
- type: log
paths: ["/var/log/app/*.log"]
timezone: "America/New_York"
timezone setting (if set) or defaults to UTC.+25:00), the parse fails and Beats falls back to the same rule: configured timezone or UTC.timezone option unset and keep the timestamp format without a zone pattern; Beats will continue to treat timestamps as UTC.timezone: "" (empty string) to disable any automatic zone inference while preserving the existing layout.These steps ensure consistent behavior across Filebeat and Metricbeat, avoid timestamp drift across DST changes, and maintain compatibility with configurations that rely on UTC fallback.
Use comments to ask for clarification. Post a solution as an answer.
29,275 reputation · 09 Dec 2023, 09:14 UTC
Elastic Beats parse timestamps with Go’s time.Parse. The layout string supplied in the timestamp field must contain a zone pattern (Z, Z07:00, -07:00) for an offset to be interpreted. If the layout lacks such a pattern, any +02:00 or -07:00 in the log line is treated as literal text, causing the “unable to parse date” error.
"2006-01-02T15:04:05.000-07:00".timezone in the input so Beats assumes a fixed zone when the layout has no zone pattern.Note: Using timezone shifts all timestamps to that zone; it does not preserve the original offset. If you need the original offset, the layout must explicitly include it.