# Custom UDP/TCP Log Timestamp

**URL:** <https://discuss.elastic.co/t/custom-udp-tcp-log-timestamp/371970>\
**Category:** Elastic Search\
**Created:** [December 13, 2024, 7:58pm UTC](https://discuss.elastic.co/t/custom-udp-tcp-log-timestamp/371970 "2024-12-13T19:58:18Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![lastshadow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lastshadow/32/130040_2.png) [@lastshadow](https://discuss.elastic.co/u/lastshadow)\
**Post date:** [December 13, 2024, 7:58pm UTC](https://discuss.elastic.co/t/custom-udp-tcp-log-timestamp/371970/1 "2024-12-13T19:58:18Z")

</div>

Hello,

I'm a newbie with Elastic so patience please. I'm using the Custom UDP Log integration in a policy on my fleet server and sending logs from rsyslog on my linux box to the fleet server. I receive the logs just fine but they are showing up with a timestamp 5 hours earlier. I see that rsyslog is sending the logs in my current timezone (EST-5) but it would appear Elastic is not reading the timezone information. Kibana is displaying the logs using my browser timezone (EST) hence why the logs show up with a timestamp 5 hours behind. tailing /var/log/syslog shows that the logs have the timezone. See below.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/8/88bd40fbf235f44a338277c091a23207750aa100.png)

Can you please suggest what I can do to have elastic show the right timestamps?

Thanks!

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [December 13, 2024, 8:20pm UTC](https://discuss.elastic.co/t/custom-udp-tcp-log-timestamp/371970/3 "2024-12-13T20:20:21Z")

</div>

If you enabled syslog parsing on the UDP integration I believe that timestamp format should be supported.

Can you share your integration configuration, a sample syslog from the device and then can you grab the document for that sample syslog from kibana by finding a log entry, clicking expand, clicking the json tab and sharing the json? Can you also share your rsyslog configuration?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2025, 8:21pm UTC](https://discuss.elastic.co/t/custom-udp-tcp-log-timestamp/371970/4 "2025-01-10T20:21:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
