# Custom filebeat module timezone conversion issue

**URL:** <https://discuss.elastic.co/t/custom-filebeat-module-timezone-conversion-issue/233428>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [May 20, 2020, 12:52am UTC](https://discuss.elastic.co/t/custom-filebeat-module-timezone-conversion-issue/233428 "2020-05-20T00:52:21Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![nmoham](https://avatars.discourse-cdn.com/v4/letter/n/77aa72/32.png) [@nmoham](https://discuss.elastic.co/u/nmoham)\
**Post date:** [May 20, 2020, 12:52am UTC](https://discuss.elastic.co/t/custom-filebeat-module-timezone-conversion-issue/233428/1 "2020-05-20T00:52:22Z")

</div>

We build a custom module for parsing F5 Load Balancer logs, all the patterns are working fine. But the timezone is set to UTC -8 hours for the event ingested and showing up in Kibana. We're currently in PT timezone.

```auto
   {
  "filebeat-7.5.2-f5-logs-pipeline" : {
    "description" : "Pipeline for parsing F5 LTM and Audit Logs",
    "processors" : [
      {
        "grok" : {
          "field" : "message",
          "patterns" : [
            "%{SYSLOGTIMESTAMP:f5.timestamp} %{IPORHOST:host.hostname} (%{LOGLEVEL:log.level})? %{PROG:process.parent.name}\\(%{NOTSPACE:process.name}\\)(?:\\[%{POSINT:process.pid:long}\\])?: %{GREEDYDATA:syslog_message}",
            "%{SYSLOGTIMESTAMP:f5.timestamp} %{IPORHOST:host.hostname} %{PROG:process.name}(?:\\[%{POSINT:process.pid:long}\\])?: %{GREEDYDATA:syslog_message}"
          ],
          "ignore_missing" : true
        }
      },
{
        "date" : {
        "if": "ctx.event?.timezone == null",            
          "field" : "f5.timestamp",
          "target_field" : "@timestamp",
          "formats" : [
            "MMM d HH:mm:ss",
            "MMM dd HH:mm:ss"
          ]
        }
      },
       {
        "date" : {
          "if": "ctx.event?.timezone != null",            
          "field" : "f5.timestamp",
          "timezone": "{{ event.timezone }}",            
          "target_field" : "@timestamp",
          "formats" : [
            "MMM d HH:mm:ss",
            "MMM dd HH:mm:ss"
          ]
        }
      },        
      {
        "date_index_name" : {
          "field" : "@timestamp",
          "date_rounding" : "d",
          "index_name_prefix" : "f5-",
          "index_name_format" : "yyyy.MM.dd",
          "ignore_failure" : false
        }
      }
    }
  }
}

```

Sample event -

"May 13 11:01:03 sysloghost notice run-parts(/etc/cron.hourly)[12939]: finished genkeys"

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/a/2a1749bcc9f5432b2e61bc2816389a40b3c8a942.png)

Followed some old threads and even tried to delete the pipeline from dev tools and then re-create the pipeline, but still the events show-up in Kibana with wrong timezone.

> [@Filebeat system module auth log timezone conversion problem](https://discuss.elastic.co/t/filebeat-system-module-auth-log-timezone-conversion-problem/140192/6):
>
> Hmmm, I suspect that the pipeline was not deleted with that command since it lives under /\_ingest not /filebeat-\* in ES. Check out the [Ingest APIs](https://www.elastic.co/guide/en/elasticsearch/reference/master/ingest-apis.html), you'll probably find the old pipeline in there, and can delete it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 17, 2020, 12:52am UTC](https://discuss.elastic.co/t/custom-filebeat-module-timezone-conversion-issue/233428/2 "2020-06-17T00:52:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
