# Changing timezone

**URL:** <https://discuss.elastic.co/t/changing-timezone/204240>\
**Category:** Logstash\
**Created:** [October 18, 2019, 2:32pm UTC](https://discuss.elastic.co/t/changing-timezone/204240 "2019-10-18T14:32:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Necus](https://avatars.discourse-cdn.com/v4/letter/n/e47774/32.png) [@Necus](https://discuss.elastic.co/u/Necus)\
**Post date:** [October 18, 2019, 2:32pm UTC](https://discuss.elastic.co/t/changing-timezone/204240/1 "2019-10-18T14:32:39Z")

</div>

Hi,  
I'm trying to change timezone for time logs, but for some reason after configuration nothing has changed. What I have done:

1. copying default date/time field:

> mutate {  
> copy =\> {"time" =\> "new\_time"}  
> }

1. changing timezone:

> date {  
> match =\> ["even\_time", "MMM dd, yyyy @ HH:mm:ss.SSS", "MMM d, yyyy @ HH:mm:ss.SSS"]  
> timezone =\> "MST"  
> target =\> "new\_time2" #I have already tried with new\_time  
> }

"new\_time" field is created correctly but unfortunatelly it has the same time zone as "time" field. I'm using [Joda-Time - Java date and time API - Time Zones](http://joda-time.sourceforge.net/timezones.html) as reference name for timezone.

time field format:  
Oct 18, 2019 @ 18:23:19.000

Any ideas?

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [October 18, 2019, 5:11pm UTC](https://discuss.elastic.co/t/changing-timezone/204240/2 "2019-10-18T17:11:42Z")

</div>

Time objects within Logstash are represented in UTC.

The `timezone` directive in the Logstash Date Filter provides _context_ for parsing the timestamp into an object representing a specific point on the timeline; once the timestamp is understood, it will be transformed into UTC for storage on the event.

I also would advise using one of the [timezonedb timezone names in the format of `"${CONTINENT}/${EXAMPLE_CITY}"`](https://en.wikipedia.org/wiki/List_of_tz_database_time_zones) (e.g., `America/Denver`), which will account for the entire ruleset of the timezone (including daylight savings switches).

---

<div class="post-metadata">

**Author:** ![Necus](https://avatars.discourse-cdn.com/v4/letter/n/e47774/32.png) [@Necus](https://discuss.elastic.co/u/Necus)\
**Post date:** [October 20, 2019, 11:21am UTC](https://discuss.elastic.co/t/changing-timezone/204240/3 "2019-10-20T11:21:31Z")

</div>

Thank you for answer, how exactly can I make this timestamp to be understood by ELK? Elasticsearch and Kibana automatically proceed with this field as the data field. What else can I change to make this right?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 17, 2019, 11:21am UTC](https://discuss.elastic.co/t/changing-timezone/204240/4 "2019-11-17T11:21:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
