# Different Timezones in syslog for some hosts

**URL:** <https://discuss.elastic.co/t/different-timezones-in-syslog-for-some-hosts/305737>\
**Category:** Logstash\
**Created:** [May 26, 2022, 5:18pm UTC](https://discuss.elastic.co/t/different-timezones-in-syslog-for-some-hosts/305737 "2022-05-26T17:18:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![syedabdullah](https://avatars.discourse-cdn.com/v4/letter/s/71c47a/32.png) [@syedabdullah](https://discuss.elastic.co/u/syedabdullah)\
**Post date:** [May 26, 2022, 5:18pm UTC](https://discuss.elastic.co/t/different-timezones-in-syslog-for-some-hosts/305737/1 "2022-05-26T17:18:47Z")

</div>

Hi Everyone, I am relatively new to ELK stack

I added a new source of syslog but that source is in UTC, When I forward the syslogs, I have its sources (hosts) in UTC and everything else in EST and once they go into Elasticsearch, it assumes everything is in UTC which puts the timestamp searching out by a few hours (Last 15 minutes to 5 hours from now filter shows the future time which is clearly UTC when viewed through Kibana). When I apply the following filter, The timestamp shows syslogs upto 4 hours into the future from my current time (e.g. if it is 13:08 in my timezone, it shows timestamps of 17:08)

Is there a way I can convert the timezones into one timezone like all into EST? Will I have to do something in the logstash conf file with the filter? or what could be the work around this? My issue is specific to one index only.

I did something like this in the filter but it didnt work and I am getting dateparsing errors

Thank you in advance.

```auto
    date {
        match => ["@timestamp", "MMM D, YYYY @ HH:mm:ss.SSS", "ISO8601"]
        timezone => "EST"
        target => "timestamp_debug"
    }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 23, 2022, 5:19pm UTC](https://discuss.elastic.co/t/different-timezones-in-syslog-for-some-hosts/305737/2 "2022-06-23T17:19:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
