I am a long time user of ELK and recently switched to 7.9 to experiment with Security and SIEM functions.
After much trouble shooting to get my test Detection to show up in the "Detection Alerts" area, I discovered by expanding my search time parameter into the future that Detections was adding ~20 minutes to my detection signal @timestamp. There are no underlying changes to the data (i.e. the correct @timestamp for a particular UID in the ES index) but the wrong @timestamp does push over into a Timeline.
All other similar timestamp type data in the detection signal such as event.created and even signal.original_event.created are unchanged (i.e. the correct time).
Note: All my zeek data renders fine in the "Network" tab WITH the correct @timestamp.
I am aware that Kibana will parse time zones into browser or other set timezone but can't find references to it adding minutes.
I would appreciate ideas on how to correct this or even how to debug it.