I have an issue with the TIMEZONE in the SECURITY – ALERTS section, the logs are received in UTC+1 in Discovery and in UTC+3 in SECURITY – ALERTS.
Knowning that the timezone configured at the kibana is in UTC+1.
- Timezone Security Alerts (UTC+3)
Please help me resolve this issue and make the time zone in UTC + 1 in the Security Alerts.
Can i find any expert to help me to resolve this issue?
Does anyone have any idea about this issue?
Has anyone encountered the same problem before?
Take a look at the docs and check the "event created" and "event.ingest" fields. May be some data source is coming with different timezone.
Check in Kibana under Stack management > Advanced settings how your time zone shown in the figure is configured.