# Convert the default ES UTC time to local timezone with logstash

**URL:** <https://discuss.elastic.co/t/convert-the-default-es-utc-time-to-local-timezone-with-logstash/361843>\
**Category:** Logstash\
**Created:** [June 21, 2024, 10:28am UTC](https://discuss.elastic.co/t/convert-the-default-es-utc-time-to-local-timezone-with-logstash/361843 "2024-06-21T10:28:36Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![gbL2k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gbl2k/32/130975_2.png) [@gbL2k](https://discuss.elastic.co/u/gbL2k)\
**Post date:** [June 21, 2024, 10:28am UTC](https://discuss.elastic.co/t/convert-the-default-es-utc-time-to-local-timezone-with-logstash/361843/1 "2024-06-21T10:28:36Z")

</div>

Hello everyone,

My goal is export alerts from elasticsearch and I have 2 problems left to solve:  
My current configuration:

```auto
input {
  elasticsearch {
    hosts => "https://ip:9200"
    index => ".internal.alerts-security.alerts-default-*"
    user => "user"
    password => "pass"
    ssl_certificate_verification => false
    query => '{ "query": { "match": { "event.dataset": "endpoint.alerts" } }, "sort": ["_doc"] }'
    schedule => "* * * * *"
    }
}

output {
  file {
    path => "/tmp/output.txt"
  }
}

```

1.How can I convert the default @timestamp (UTC) field coming from elastic to my timezone?  
2.How can I query documents only in the last x minutes?(With the current configuration logstash retrieves every document every time it runs.)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 21, 2024, 10:52am UTC](https://discuss.elastic.co/t/convert-the-default-es-utc-time-to-local-timezone-with-logstash/361843/2 "2024-06-21T10:52:47Z")

</div>

> [@gbL2k](#):
>
> How can I convert the default @timestamp (UTC) field coming from elastic to my timezone?

There is an example of that [here](https://discuss.elastic.co/t/convert-datetime-to-another-timezone-in-logstash/336214/9).

---

<div class="post-metadata">

**Author:** ![gbL2k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gbl2k/32/130975_2.png) [@gbL2k](https://discuss.elastic.co/u/gbL2k)\
**Post date:** [June 25, 2024, 9:30am UTC](https://discuss.elastic.co/t/convert-the-default-es-utc-time-to-local-timezone-with-logstash/361843/3 "2024-06-25T09:30:07Z")

</div>

Can you exaplain what it does?  
For my understanding it just creates an rt field and sets the localtime with a value +8 hours from that date.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 25, 2024, 10:05am UTC](https://discuss.elastic.co/t/convert-the-default-es-utc-time-to-local-timezone-with-logstash/361843/4 "2024-06-25T10:05:46Z")

</div>

> [@gbL2k](#):
>
> For my understanding it just creates an rt field and sets the localtime with a value +8 hours from that date.

That's right. If a document has an [rt] field in UTC it creates another field in localtime (provided localtime is MYT -- it would have to be adjusted for other local timezones).

When you asked "How can I convert the default @timestamp (UTC) field coming from elastic to my timezone?" I thought that was what you wanted.

---

<div class="post-metadata">

**Author:** ![gbL2k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gbl2k/32/130975_2.png) [@gbL2k](https://discuss.elastic.co/u/gbL2k)\
**Post date:** [June 25, 2024, 10:20am UTC](https://discuss.elastic.co/t/convert-the-default-es-utc-time-to-local-timezone-with-logstash/361843/5 "2024-06-25T10:20:19Z")

</div>

My goal is to have a field that contains the timestamp coming from the @timestamp field(utc) in my local timezone gmt+2.  
I made some changes to the configuration,it creates the timestamp\_zoned field but the date is the same as in the original @timestamp field. :

```auto
filter {

    mutate {
        add_field => {
            "timestamp_zoned" => "%{@timestamp}"
        }
    }

    date {
        match => ["timestamp_zoned", "yyyy-MM-dd HH:mm:ss'Z'"]
        timezone => "Europe/Budapest"
        target => "timestamp_zoned"
    }

}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 25, 2024, 10:29am UTC](https://discuss.elastic.co/t/convert-the-default-es-utc-time-to-local-timezone-with-logstash/361843/6 "2024-06-25T10:29:28Z")

</div>

> [@gbL2k](#):
>
> ```auto
> date {
> match => ["timestamp_zoned", "yyyy-MM-dd HH:mm:ss'Z'"]
> timezone => "Europe/Budapest"
> target => "timestamp_zoned"
> }
> 
> ```

The Z at the end of the [timestamp\_zoned] indicates it is in Zulu (UTC). The timezone option on the date filter is ignored in that case.

---

<div class="post-metadata">

**Author:** ![gbL2k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gbl2k/32/130975_2.png) [@gbL2k](https://discuss.elastic.co/u/gbL2k)\
**Post date:** [June 25, 2024, 10:47am UTC](https://discuss.elastic.co/t/convert-the-default-es-utc-time-to-local-timezone-with-logstash/361843/7 "2024-06-25T10:47:35Z")

</div>

Thanks for the information I didnt know that.  
I removed it but nothing changed ☹ .

---

<div class="post-metadata">

**Author:** ![gbL2k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gbl2k/32/130975_2.png) [@gbL2k](https://discuss.elastic.co/u/gbL2k)\
**Post date:** [June 25, 2024, 12:50pm UTC](https://discuss.elastic.co/t/convert-the-default-es-utc-time-to-local-timezone-with-logstash/361843/8 "2024-06-25T12:50:26Z")

</div>

Any idea?  
I have none, I tried everything I could find to solve this problem.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 25, 2024, 1:44pm UTC](https://discuss.elastic.co/t/convert-the-default-es-utc-time-to-local-timezone-with-logstash/361843/9 "2024-06-25T13:44:19Z")

</div>

> [@gbL2k](#):
>
> I tried everything I could find to solve this problem

What exactly is the problem? You described an issue and I provided a link to what I thought was a solution. If it is not a solution then I need a better problem definition.

---

<div class="post-metadata">

**Author:** ![gbL2k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gbl2k/32/130975_2.png) [@gbL2k](https://discuss.elastic.co/u/gbL2k)\
**Post date:** [June 25, 2024, 1:51pm UTC](https://discuss.elastic.co/t/convert-the-default-es-utc-time-to-local-timezone-with-logstash/361843/10 "2024-06-25T13:51:23Z")

</div>

I receive a UTC timestamp from elastic in the @timestamp field.  
My goal is to create a new field from that timestamp field in my timezone(GMT+2).  
For example:  
I have the following the document that is coming from ES.

```auto
    "@timestamp": [
      "2024-06-11T14:58:20.420Z"
    ],

```

I want to have a field that contains the time in my local timezone(+2 hours difference):

```auto
    "localtime": [
      "2024-06-11T16:58:20.420Z"
    ],

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 25, 2024, 2:03pm UTC](https://discuss.elastic.co/t/convert-the-default-es-utc-time-to-local-timezone-with-logstash/361843/11 "2024-06-25T14:03:51Z")

</div>

OK, so you need to tweak the ruby code slightly

```
input { generator { count => 1 lines => ['{ "@timestamp": "2024-06-11T14:58:20.420Z" }'] codec => json } }

output { stdout { codec => rubydebug { metadata => false } } }
filter {
    ruby {
        code => '
            t = event.get("[@timestamp]").to_f
            t = Time.at(t, in: "+02:00")
            event.set("localtime", t.strftime("%Y-%m-%dT%H:%M:%S.%LZ"))
        '
    }
    date { match => ["localtime", "ISO8601"] target => "localtime_as_timestamp" }
}

```

will produce

```
             "localtime" => "2024-06-11T16:58:20.420Z",
            "@timestamp" => 2024-06-11T14:58:20.420Z,
"localtime_as_timestamp" => 2024-06-11T16:58:20.420Z

```

---

<div class="post-metadata">

**Author:** ![gbL2k](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gbl2k/32/130975_2.png) [@gbL2k](https://discuss.elastic.co/u/gbL2k)\
**Post date:** [June 25, 2024, 2:11pm UTC](https://discuss.elastic.co/t/convert-the-default-es-utc-time-to-local-timezone-with-logstash/361843/12 "2024-06-25T14:11:10Z")

</div>

It works!

Thanks a lot!
