# Delay of one hour in the events to ELK

**URL:** https://discuss.elastic.co/t/delay-of-one-hour-in-the-events-to-elk/347875
**Category:** Beats
**Tags:** elastic-stack-monitoring, filebeat
**Created:** [November 23, 2023, 3:23pm UTC](https://discuss.elastic.co/t/delay-of-one-hour-in-the-events-to-elk/347875 "2023-11-23T15:23:40Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![billy.castillo.73](https://avatars.discourse-cdn.com/v4/letter/b/6f9a4e/32.png) [@billy.castillo.73](https://discuss.elastic.co/u/billy.castillo.73)
#### Post date: [November 23, 2023, 3:23pm UTC](https://discuss.elastic.co/t/delay-of-one-hour-in-the-events-to-elk/347875/1 "2023-11-23T15:23:40Z")

</div>

The events of a system that are being parsed from filebeat to our ELK are arriving an hour late.

I have already configured the netscout.yml module of filebeat with the grok processors, with var.tz\_offset and with date - timezone so that they arrive correctly at time +1, but it has not worked, it always remains the same.

For example, it is 22:47 and when I check an event the timestamp fields has the time 21:47 and the event.original field also has the time 21:47, only the event.ingest field has the correct time which would be 22:47.

How can I solve the events of this equipment, because events from other equipment (Firewall, DDoS) arrive correctly.

Thank you very much.

 ![2023-11-22 22_49_05-d](https://us1.discourse-cdn.com/elastic/original/3X/1/0/10ebb5ce455c7d3c89ff7a5a892a9e59f34de5ca.png)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 21, 2023, 5:24pm UTC](https://discuss.elastic.co/t/delay-of-one-hour-in-the-events-to-elk/347875/2 "2023-12-21T17:24:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
