# Change time zone using date filter

**URL:** <https://discuss.elastic.co/t/change-time-zone-using-date-filter/325461>\
**Category:** Logstash\
**Created:** [February 14, 2023, 11:25am UTC](https://discuss.elastic.co/t/change-time-zone-using-date-filter/325461 "2023-02-14T11:25:24Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [February 14, 2023, 11:25am UTC](https://discuss.elastic.co/t/change-time-zone-using-date-filter/325461/1 "2023-02-14T11:25:24Z")

</div>

Hi there,

i have a problem with timezone in date filter. so this is the situation:  
i have a field contain an epoch timestamp like this

 ![gambar](https://us1.discourse-cdn.com/elastic/original/3X/2/6/269ff7f230babc8a1286ea7c449c5e60285760f8.png)

i try to convert it using date filter like this but it didn't work

```auto
mutate{
        convert => {
        "[service][updated_at]" => "string"
        }
        strip => ["[service][updated_at]"]
}
   date {
        match => ["[service][updated_at]", "UNIX_MS"]
        target => "[service_updated_at]"
        timezone => "+07:00"
   }

```

i already define timezone there but i don't know why the result becomes like this:

 ![gambar](https://us1.discourse-cdn.com/elastic/original/3X/0/8/089a0b68c9a84ab384885230f2807be03e07a6b0.png)

for comparison, if i try to paste the number in epoch site, it tells me the correct date  
 ![gambar](https://us1.discourse-cdn.com/elastic/original/3X/8/f/8f4f7380f4e4738472aceeecfd91b02faa0e0f70.png)

anybody knows how to fix this? please help.

Thanks

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 14, 2023, 11:45am UTC](https://discuss.elastic.co/t/change-time-zone-using-date-filter/325461/2 "2023-02-14T11:45:56Z")

</div>

> [@yuswanul](#):
>
> ```auto
> date {
> match => ["[service][updated_at]", "UNIX_MS"]
> target => "[service_updated_at]"
> timezone => "+07:00"
> }
> 
> ```

This is not correct and it is a common confusion, the `timezone` option in the `date` plugin on logstash should not be used to change the timezone of the value, it should be used when you have a date string without any timezone information and the date string is not on UTC because both Logstash and Elasticsearch works with UTC.

If your date string already has timezone information you should not use the `timezone` option of the `date` filter.

Since your date string is on unix epoch, it is already on UTC, so you cannot use the timezone option in the logstash date filter, using it will add a 7 hours offset to the UTC date.

So the date `2023-02-09 10:41:21 UTC` will become `2023-02-09 17:41:21 UTC`, and when Kibana shows up dates it will per default convert the UTC value to the browser timezone, if you are on a `+0700` timezone, Kibana will add this to the UTC date you will have `2023-02-10 00:41:21` on Discover.

You need to remove the `timezone` option from the date filte as your date string is already in UTC.

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [February 15, 2023, 3:24am UTC](https://discuss.elastic.co/t/change-time-zone-using-date-filter/325461/3 "2023-02-15T03:24:32Z")

</div>

> [@leandrojmp](#):
>
> Since your date string is on unix epoch, it is already on UTC, so you cannot use the timezone option in the logstash date filter, using it will add a 7 hours offset to the UTC date.

sorry, maybe i forgot to explain, but that's my goal to change the timezone to GMT +7. that's why I added the timezone option and thanks for your response. i have solved this problem. I tried changing UNIX\_MS to UNIX and it worked for me. I don't know why this happened? I see from the documentation there is no significant difference between UNIX and UNIX\_MS. Why do you think this works by matching the data to UNIX?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 15, 2023, 3:33am UTC](https://discuss.elastic.co/t/change-time-zone-using-date-filter/325461/4 "2023-02-15T03:33:05Z")

</div>

> [@yuswanul](#):
>
> sorry, maybe i forgot to explain, but that's my goal to change the timezone to GMT +7. that's why I added the timezone option

In general I would recommend against this. elasticsearch expects all times to be in UTC (if you were feeding some other downstream system then I would have no issue at all with doing this). Programs consuming data from elasticsearch will expect times to be in UTC (kibana will change them to the browser's timeone by default). If you are sure everyone consuming the data (now or in the future) is happy with the timezone shift then you should be OK, but, as I said, I recommend against it.

> [@yuswanul](#):
>
> there is no significant difference between UNIX and UNIX\_MS

One is in seconds, one in milliseconds, at the time of writing UNIX would be 1676431668, UNIX\_MS would be 1676431668000.

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [February 15, 2023, 3:50am UTC](https://discuss.elastic.co/t/change-time-zone-using-date-filter/325461/5 "2023-02-15T03:50:40Z")

</div>

ok, i think it's pretty clear. thanks for the explanation @Badger @leandrojmp

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 15, 2023, 12:37pm UTC](https://discuss.elastic.co/t/change-time-zone-using-date-filter/325461/6 "2023-02-15T12:37:36Z")

</div>

> [@yuswanul](#):
>
> sorry, maybe i forgot to explain, but that's my goal to change the timezone to GMT +7.

I also would not recommend that, you are adding a timezone offset to a date that has no timezone offset.

Elasticsearch works with UTC dates and unix epoch is already in UTC, when you add a timezone to a UTC date you are changing the original date saying that it happened on a different time and this can leads to confusion or even auditing problems if you have any audit on your systems.

But if you are sure that everyone that uses your systems knows about this change, then it would not be so much of a problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 15, 2023, 12:37pm UTC](https://discuss.elastic.co/t/change-time-zone-using-date-filter/325461/7 "2023-03-15T12:37:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
