# \[ELK\]logstash default timezone cause index splitting problem in different timezones

**URL:** <https://discuss.elastic.co/t/elk-logstash-default-timezone-cause-index-splitting-problem-in-different-timezones/26615>\
**Category:** Logstash\
**Created:** [July 31, 2015, 6:09am UTC](https://discuss.elastic.co/t/elk-logstash-default-timezone-cause-index-splitting-problem-in-different-timezones/26615 "2015-07-31T06:09:22Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![Weiwei\_Wang](https://avatars.discourse-cdn.com/v4/letter/w/b19c9b/32.png) [@Weiwei\_Wang](https://discuss.elastic.co/u/Weiwei_Wang)\
**Post date:** [July 31, 2015, 6:09am UTC](https://discuss.elastic.co/t/elk-logstash-default-timezone-cause-index-splitting-problem-in-different-timezones/26615/1 "2015-07-31T06:09:22Z")

</div>

I'm a Chinese developer, our timezone is +08:00，the problem using logstash is that @timestamp is always formatted as @timestamp" =\> "2015-07-25T16:00:30.000Z, the input time is 2015-07-26 00:00:30. This problem will cause 1 day log to be spliced to two indexes:logstash-2015.07.25 and logstash-2015-07.26

I tried to fix it by add logged\_date field to represent 2015-07-26 in +08:00 timezone, however, in kibana, all the date fields will be added 08:00 hours, which causes incorrect logged\_date in Chinese timezone

Could anyone give me a solution on this problem? I googled around and found no proper solution.

I've read the user guide for logstash date filter, the timezone parameter for date filter is used to parse input log time not for output, so it cannot be used to change the output @timestamp timezone

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 31, 2015, 6:43am UTC](https://discuss.elastic.co/t/elk-logstash-default-timezone-cause-index-splitting-problem-in-different-timezones/26615/2 "2015-07-31T06:43:30Z")

</div>

ES and LS use UTC as much as possible to make it standardised.

If you are using KB then it shouldn't be a problem, as it will change the times to the TZ of the browser.

---

<div class="post-metadata">

**Author:** ![Weiwei\_Wang](https://avatars.discourse-cdn.com/v4/letter/w/b19c9b/32.png) [@Weiwei\_Wang](https://discuss.elastic.co/u/Weiwei_Wang)\
**Post date:** [August 1, 2015, 4:24am UTC](https://discuss.elastic.co/t/elk-logstash-default-timezone-cause-index-splitting-problem-in-different-timezones/26615/3 "2015-08-01T04:24:08Z")

</div>

yes, es and logstash use utc 00:00 is ok for kibana, but logstash elasticsearch output plugin use @timestamp to format the index\_name, as a result, one day log in +08:00 timezone will be indexed into two different indexes, which is confused for us in +08:00 timezone，although, kibana will fix this problem when displaying query result

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 1, 2015, 7:18am UTC](https://discuss.elastic.co/t/elk-logstash-default-timezone-cause-index-splitting-problem-in-different-timezones/26615/4 "2015-08-01T07:18:50Z")

</div>

Again, this is by design and nothing you should try to "fix".

---

<div class="post-metadata">

**Author:** ![danielwalker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielwalker/32/14396_2.png) [@danielwalker](https://discuss.elastic.co/u/danielwalker)\
**Post date:** [December 28, 2016, 5:19am UTC](https://discuss.elastic.co/t/elk-logstash-default-timezone-cause-index-splitting-problem-in-different-timezones/26615/5 "2016-12-28T05:19:17Z")

</div>

Hi, I want to know your solution for this. We have also the problem. As known to us all that logstash will use UTC and kibana automatically converts the timezone to user's browsers local time, which is fine.

But we also want to use filebeat and logstash, instead of parsing and sending data to elasticsearch, we just want to keep the log files and spliced them in server's local time, and use our customized scripts to parse the log files.

So, is there any way to configure the logstash settings to generating log files in server time instead of in UTC?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 28, 2016, 6:02am UTC](https://discuss.elastic.co/t/elk-logstash-default-timezone-cause-index-splitting-problem-in-different-timezones/26615/6 "2016-12-28T06:02:16Z")

</div>

Nope.

---

<div class="post-metadata">

**Author:** ![danielwalker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielwalker/32/14396_2.png) [@danielwalker](https://discuss.elastic.co/u/danielwalker)\
**Post date:** [January 9, 2017, 8:39am UTC](https://discuss.elastic.co/t/elk-logstash-default-timezone-cause-index-splitting-problem-in-different-timezones/26615/7 "2017-01-09T08:39:19Z")

</div>

OK, but personally speaking, I think using logstash and filebeat to keep the log splited in localtime is a necessity.

---

<div class="post-metadata">

**Author:** ![fadjar340](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fadjar340/32/43610_2.png) [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Post date:** [January 23, 2017, 6:42pm UTC](https://discuss.elastic.co/t/elk-logstash-default-timezone-cause-index-splitting-problem-in-different-timezones/26615/8 "2017-01-23T18:42:30Z")

</div>

As my experience,  
i have several jdbc input in the logstash conf.d file, and I use the config for one stanza like below:

jdbc { #4  
jdbc\_driver\_library =\> "/opt/elasticsearch-jdbc-2.3.4.0/lib/mysql-connector-java-5.1.38.jar"  
jdbc\_driver\_class =\> "com.mysql.jdbc.Driver"  
jdbc\_connection\_string =\> "jdbc:mysql://192.168.xxx.xxx:3306/myschema"  
jdbc\_user =\> "xxxxxx"  
jdbc\_password =\> "xxxxxxx"  
jdbc\_paging\_enabled =\> "true"  
jdbc\_page\_size =\> 50000  
schedule =\> "\*/15 \* \* \* \*"  
last\_run\_metadata\_path =\> "/data/metadata/myindex\_last\_run.txt"  
jdbc\_default\_timezone =\> "UTC"  
statement =\> "select \* from sales where sales\_date \> :sql\_last\_value"  
type =\> "my\_type"  
}

the myindex\_last\_run.txt as  
--- 2017-01-23 18:30:00.297000000 Z

Before I use jdbc\_default\_timezone =\> "UTC", my query will follow the myindex\_last\_run.txt that stored in UTC, so the log said that:  
select \* from sales where sales\_date \> '2017-01-23 18:30:00' \<== Wrong

After I use the jdbc\_default\_timezone =\> "UTC" then my query change to  
select \* from sales where sales\_date \> '2017-01-24 01:30:00' \<== right value

I'm frustrated for several weeks and just remove the document that doubled by the query when I restart the logstash.  
Now, I can sleep well with this configuration.... 🙂

That's my 50 cents...

Thanks...

Fadjar Tandabawana

---

<div class="post-metadata">

**Author:** ![qin](https://avatars.discourse-cdn.com/v4/letter/q/91b2a8/32.png) [@qin](https://discuss.elastic.co/u/qin)\
**Post date:** [April 1, 2017, 1:17pm UTC](https://discuss.elastic.co/t/elk-logstash-default-timezone-cause-index-splitting-problem-in-different-timezones/26615/9 "2017-04-01T13:17:46Z")

</div>

你问题解决了吗？

---

<div class="post-metadata">

**Author:** ![danielwalker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielwalker/32/14396_2.png) [@danielwalker](https://discuss.elastic.co/u/danielwalker)\
**Post date:** [April 11, 2017, 2:39am UTC](https://discuss.elastic.co/t/elk-logstash-default-timezone-cause-index-splitting-problem-in-different-timezones/26615/10 "2017-04-11T02:39:05Z")

</div>

没有解决

---

<div class="post-metadata">

**Author:** ![Champion\_Xie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/champion_xie/32/71770_2.png) [@Champion\_Xie](https://discuss.elastic.co/u/Champion_Xie)\
**Post date:** [April 21, 2017, 9:00am UTC](https://discuss.elastic.co/t/elk-logstash-default-timezone-cause-index-splitting-problem-in-different-timezones/26615/11 "2017-04-21T09:00:58Z")

</div>

kibana默认的时区是UTC 所以在kibana页面上看貌似是logstash在入ES时把一天的数据分到两个索引里，但其实统计的时候不是这样的，你需要在kibana的设置里设置下浏览器时区就可以显示对了

比如你如21号的数据 ，在kibana里看确实前8个小时在20号的索引里，但其实统计不是那个样子的 不过logstash在filter的时候需要定义好与日志时间一直的时间戳即可

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 21, 2017, 9:04am UTC](https://discuss.elastic.co/t/elk-logstash-default-timezone-cause-index-splitting-problem-in-different-timezones/26615/12 "2017-04-21T09:04:13Z")

</div>

Folks, please use English here. There's a Chinese group available if you want to post in Chinese.

---

<div class="post-metadata">

**Author:** ![danielwalker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielwalker/32/14396_2.png) [@danielwalker](https://discuss.elastic.co/u/danielwalker)\
**Post date:** [April 21, 2017, 9:13am UTC](https://discuss.elastic.co/t/elk-logstash-default-timezone-cause-index-splitting-problem-in-different-timezones/26615/13 "2017-04-21T09:13:56Z")

</div>

Ok, sorry for any inconveniences caused.

---

<div class="post-metadata">

**Author:** ![danielwalker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielwalker/32/14396_2.png) [@danielwalker](https://discuss.elastic.co/u/danielwalker)\
**Post date:** [April 21, 2017, 9:17am UTC](https://discuss.elastic.co/t/elk-logstash-default-timezone-cause-index-splitting-problem-in-different-timezones/26615/14 "2017-04-21T09:17:53Z")

</div>

Not really.

Kibana converts the UTC based data to client browser's timezone, which is pretty fine when using the ES + Kibana + Logstash stack.

What I am asking about is how to change the logstash's default timezone to Beijing Time, then use file plugin to ship data to write to disk for storage only, instead of into ES.

---

<div class="post-metadata">

**Author:** ![Champion\_Xie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/champion_xie/32/71770_2.png) [@Champion\_Xie](https://discuss.elastic.co/u/Champion_Xie)\
**Post date:** [April 24, 2017, 7:49am UTC](https://discuss.elastic.co/t/elk-logstash-default-timezone-cause-index-splitting-problem-in-different-timezones/26615/15 "2017-04-24T07:49:18Z")

</div>

oh sorry

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:26am UTC](https://discuss.elastic.co/t/elk-logstash-default-timezone-cause-index-splitting-problem-in-different-timezones/26615/16 "2017-07-06T04:26:56Z")

</div>


