# EET Time converted to UTC....... why?

**URL:** <https://discuss.elastic.co/t/eet-time-converted-to-utc-why/88021>\
**Category:** Logstash\
**Created:** [June 2, 2017, 6:52am UTC](https://discuss.elastic.co/t/eet-time-converted-to-utc-why/88021 "2017-06-02T06:52:02Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [June 2, 2017, 6:52am UTC](https://discuss.elastic.co/t/eet-time-converted-to-utc-why/88021/1 "2017-06-02T06:52:03Z")

</div>

Hi,  
I have below configuration to logstash indexer.

```
 grok {
                 match => { "message" => "%{TIMESTAMP_ISO8601:logTime}" }
         }

```

log message:  
`2017-06-02 08:28:59,335 | INFO acknowledgeMessages Acknowledging 1 messages up to message id ID:43bf1b4f-59c7-311d-a661-fe4978998ac3`

As per the indexer configuration, expected logTime field value should be : 2017-06-02 08:28:59,335

However, When I get query, it shows 2017-06-02T05:28:59.335Z. Exactly 3 hours less than actual time. All the servers are in same timezone. Logstash/elasticsearc/Kibana browser

```
"_source":
                {
                    "@timestamp": "2017-06-02T05:29:04.072Z",
                    "Application": "myApp",
                   "beat":
                    {
                    },
                    "count": 1,
                    "message": "2017-06-02 08:28:59,335 | INFO acknowledgeMessages Acknowledging 1 messages up to message id ID:43bf1b4f-59c7-311d-a661-fe4978998ac3.",
                    "offset": 820439,
                    "source": "/var/log//wrapper_20170602.log",
                    "type": "info",
                    "@version": "1",
                    **"logTime": "2017-06-02T05:28:59.335Z"**
                }

```

its not problem for KIbana. In Kibana it shows me correct value as expected: 2017-06-02 08:28:59,335  
Its creating problem for me when I set up elastalert over it. When I receive an email from elastalert, it shows the time stored in ES.  
logTime: 2017-06-02T05:28:59.335Z. This creates confusion to the recipient, because actual timestamp is message is "2017-06-02 08:28:59,335" and it shows 3 hours less than it.  
Can anybody tell me whats happening over here? What changes I have to do?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 2, 2017, 7:04am UTC](https://discuss.elastic.co/t/eet-time-converted-to-utc-why/88021/2 "2017-06-02T07:04:07Z")

</div>

LS and ES assume UTC.  
If you want to change that then use a date filter and set the TZ accordingly.

---

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [June 2, 2017, 7:49am UTC](https://discuss.elastic.co/t/eet-time-converted-to-utc-why/88021/3 "2017-06-02T07:49:25Z")

</div>

Hi,  
Thanks for comment.  
Change in elastalert code solved my problem.  
I made elastalert to behave like kibana 🙂 This made possible to change logTime back to local timezone from UTC.

Cheers,  
Sunil.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 2, 2017, 7:50am UTC](https://discuss.elastic.co/t/eet-time-converted-to-utc-why/88021/4 "2017-06-02T07:50:26Z")

</div>

> [@sunilmchaudhari](#):
>
> Change in elastalert code solved my problem.

Not really, you've just shifted it somewhere else!

---

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [June 2, 2017, 7:50am UTC](https://discuss.elastic.co/t/eet-time-converted-to-utc-why/88021/5 "2017-06-02T07:50:59Z")

</div>

Oh!  
Can you please elaborate?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 2, 2017, 8:00am UTC](https://discuss.elastic.co/t/eet-time-converted-to-utc-why/88021/6 "2017-06-02T08:00:42Z")

</div>

Like I said, ES and LS work off UTC.  
If you integrate anything else into ES then you have to tell it that the time it is receiving is not UTC. So all you have done is shift the problem onto this client and any future ones.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 30, 2017, 8:01am UTC](https://discuss.elastic.co/t/eet-time-converted-to-utc-why/88021/7 "2017-06-30T08:01:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
