FileBeat Assumes UTC


(Jon Dison) #1

There is a closed thread here:

Where @andrewkroh says, "I would recommend running all your systems with UTC time..."
Does that mean all systems in the Elastic stack? Or all systems that we'd ever want to ingest logs from? If the Elastic stack needs to be in UTC time, we can head in that direction, but we are a MSP for clients in multiple timezones and as such cannot control which time zones the customer systems are in.


(Andrew Kroh) #2

If you are referring to the Filebeat system module parsing syslog messages, then you can enable the convert_timezone option in the module to ensure the proper timezone is used with parsing the timestamps. See https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-system.html#_literal_syslog_literal_fileset_settings.