I have installed a new instance of Elasticsearch 7.3 and configured one host to send Filebeat data with Auditd and System modules. The auditd logs look correct. The System module collected data will not stop converting the timezone to UTC. When I view the logs in Kibana, everything picked up by the system module shows the data time as UTC. This was previously fixed by uncommenting and setting the var convert timezone setting to true in the system.yml file. I then set the filebeat.yml to add_locale with the abbreviation. That resulted in the an error in processing that indicates PDT - the timezone the server is running in - as an unknown Timezone ID.
It seems somethings have changed in version 7.3.