# Filebeat 6.4.2 the timestamp is not right

**URL:** <https://discuss.elastic.co/t/filebeat-6-4-2-the-timestamp-is-not-right/151748>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 10, 2018, 5:07am UTC](https://discuss.elastic.co/t/filebeat-6-4-2-the-timestamp-is-not-right/151748 "2018-10-10T05:07:44Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [October 10, 2018, 5:07am UTC](https://discuss.elastic.co/t/filebeat-6-4-2-the-timestamp-is-not-right/151748/1 "2018-10-10T05:07:44Z")

</div>

filebeat 6.4.2 the timestamp is not right.  
i use filebeat 6.4.2 to es  
the time is +8 not right  
my machine timezone is  
`Wed Oct 10 13:03:45 CST 2018`  
but the filebeat time write into es is like  
`"@timestamp" : "2018-10-10T12:58:01.000Z",`  
how can change it the @timestamp -8 hours .  
when search this not ok.  
in system.yml at /etc/filebeat/modules.d

```
- module: system
  # Syslog
  syslog:
    enabled: true

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    #var.paths:

    # Convert the timestamp to UTC. Requires Elasticsearch >= 6.1.
    var.convert_timezone: false
    #var.convert_timezone: true

  # Authorization logs
  auth:
    enabled: true

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    #var.paths:

    # Convert the timestamp to UTC. Requires Elasticsearch >= 6.1.
    var.convert_timezone: false
    #var.convert_timezone: true

```

**the var.convert\_timezone use true or false when my timezone is not UTC ,it's CST?**

---

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [October 11, 2018, 2:32am UTC](https://discuss.elastic.co/t/filebeat-6-4-2-the-timestamp-is-not-right/151748/2 "2018-10-11T02:32:00Z")

</div>

the time in my CST time zone why +8 hours to now .this need -8 hours but the filebeat nothing to it.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 12, 2018, 11:24pm UTC](https://discuss.elastic.co/t/filebeat-6-4-2-the-timestamp-is-not-right/151748/3 "2018-10-12T23:24:30Z")

</div>

Filebeat itself reports the timestamp in UTC-0. When `convert_timezone` is configured to `true`, then filebeat adds the `add_locale` processor, adding timezone information to events. Plus it adds a `date` filter to the ingest node pipeline. The final conversion is done by Elasticsearch using the ingest node pipeline.

When updating the filebeat configuration, the ingest node pipeline is normally not updated. You can use the `filebeat.overwrite_pipelines` setting to force the pipeline to be updated. See the `filebeat.reference.yml` file.

---

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [October 17, 2018, 2:20am UTC](https://discuss.elastic.co/t/filebeat-6-4-2-the-timestamp-is-not-right/151748/4 "2018-10-17T02:20:34Z")

</div>

i set it but not ok running..

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [October 17, 2018, 12:14pm UTC](https://discuss.elastic.co/t/filebeat-6-4-2-the-timestamp-is-not-right/151748/5 "2018-10-17T12:14:44Z")

</div>

What do you mean by that? Is the pipeline not updated? Do you see an error?

Alternatively, you could run `./filebeat setup --pipelines -modules=system`. This also updates the pipelines of `system` module.

---

<div class="post-metadata">

**Author:** ![zqc0512](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zqc0512/32/32141_2.png) [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Post date:** [October 18, 2018, 2:38am UTC](https://discuss.elastic.co/t/filebeat-6-4-2-the-timestamp-is-not-right/151748/6 "2018-10-18T02:38:43Z")

</div>

slove it neet change the timezone to cst in pipeline in es with name is filebeat-6.4.2-system-syslog-pipeline

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 15, 2018, 4:38am UTC](https://discuss.elastic.co/t/filebeat-6-4-2-the-timestamp-is-not-right/151748/7 "2018-11-15T04:38:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
