# Filebeat incorrect timestamp

**URL:** <https://discuss.elastic.co/t/filebeat-incorrect-timestamp/189009>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 5, 2019, 6:06am UTC](https://discuss.elastic.co/t/filebeat-incorrect-timestamp/189009 "2019-07-05T06:06:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marct](https://avatars.discourse-cdn.com/v4/letter/m/c57346/32.png) [@Marct](https://discuss.elastic.co/u/Marct)\
**Post date:** [July 5, 2019, 6:06am UTC](https://discuss.elastic.co/t/filebeat-incorrect-timestamp/189009/1 "2019-07-05T06:06:20Z")

</div>

Hi,

Very new to Elastic and all things ELK...  
I have started a trail instance of Cloud ES on version 7.2.0, I am testing the panw filebeat module to ship my firewall logs to ES. I have followed what I though to be the correct path for installing filebeat but my log times are skewed by +2 hours.  
The config is very basic so I may be missing a setting the only changes I have made is to provide my cloudid instance and credentials as well as enable to panw module then run the setup for filebeat.

Firewall is set to Africa/Johannesburg, PC with filebeat loaded is set to Africa/Johannesburg and ES time zone in advanced is also set (All times are UTC +2)  
When looking at the logs in ES this is represented

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/d/7df37db920d2786c5de6f24559b06b70535fea49.png)

Looking through the Discover tab I see the `@timestamp` value is correct from the JSON

`"fields": {"@timestamp": ['2019-07-05T08:01:54.000Z"`

But ES is recording it with an additional 2 hours.

Any help would be greatly appreciated

---

<div class="post-metadata">

**Author:** ![faec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faec/32/46988_2.png) [@faec](https://discuss.elastic.co/u/faec)\
**Post date:** [July 5, 2019, 9:41pm UTC](https://discuss.elastic.co/t/filebeat-incorrect-timestamp/189009/2 "2019-07-05T21:41:10Z")

</div>

What I believe you're seeing is that the timestamp is recorded in UTC (which should typically be the case for all logged timestamps) but the UI is showing you the parsed timestamp in your local time -- that is, the underlying data is correct, it's just the viewer that is causing the apparent skew. Unless you see some other sign that the raw data fields are also receiving the wrong time, I wouldn't worry about this.

---

<div class="post-metadata">

**Author:** ![Marct](https://avatars.discourse-cdn.com/v4/letter/m/c57346/32.png) [@Marct](https://discuss.elastic.co/u/Marct)\
**Post date:** [July 6, 2019, 6:00pm UTC](https://discuss.elastic.co/t/filebeat-incorrect-timestamp/189009/3 "2019-07-06T18:00:33Z")

</div>

Thanks for the answer, the raw logs received in to ES were in my local timezone, but ES what I think was happening was ES assumed they were UTC and added +2 hours when storing them which meant I could not see any data unless I moved the time scale 2 hours forward.

After modifying the `manifest.yml` file in the panw modules folder to the following everything seemed to resolve and the logs and timestamps are now correct

`- name: convert_timezone`  
`default: true`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 3, 2019, 6:00pm UTC](https://discuss.elastic.co/t/filebeat-incorrect-timestamp/189009/4 "2019-08-03T18:00:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
