I have some auth0 logs streamed via Logstash where I use date filter to capture the date from the message itself.
In the message the date is in the form of: 2018-02-19T00:35:32.145Z
My date filter looks like this:
match => [ "date", "YYYY-MM-dd'T'HH:mm:ss.SSS'Z'"]
timezone => "Australia/Melbourne"
In Kibana: Advanced settings set to: dateFormat:tz - Browser (I was playing and changing it to Australia/Melbourne but no luck)
Indexed dates are:
date coming from the message: 2018-02-19T00:35:32.145Z
date created by the "date" plugin: 2018-02-18T13:35:32.145Z
current AEDT date: February 19th 2018, 11:35:32
In Kibana I search for events and search is going by the current Australian time (That's also what I want it to be). But events appearing in the past due to the UTC time in the index.
How can I fix it - The search for events and the @timestamp presentation in local time?