# Filebeat system and iptables module timezone offset issue

**URL:** <https://discuss.elastic.co/t/filebeat-system-and-iptables-module-timezone-offset-issue/176732>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 13, 2019, 11:12am UTC](https://discuss.elastic.co/t/filebeat-system-and-iptables-module-timezone-offset-issue/176732 "2019-04-13T11:12:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mback2k](https://avatars.discourse-cdn.com/v4/letter/m/53a042/32.png) [@mback2k](https://discuss.elastic.co/u/mback2k)\
**Post date:** [April 13, 2019, 11:12am UTC](https://discuss.elastic.co/t/filebeat-system-and-iptables-module-timezone-offset-issue/176732/1 "2019-04-13T11:12:14Z")

</div>

Hello everyone,

I am using filebeat 6.7.1 with the system, iptables, traefik and apache2 modules. For some reason I am having issues with @timestamp being incorrect for system (from /var/log/syslog\* and /var/log/auth.log\*) and iptables (from /var/log/kern.log\*) logs.

These logs are written with timestamps according to the timezone CET / CEST (Europe/Berlin), currently UTC+2. Filebeat is running in a container with the same timezone information. `date` gives the same date, time and timezone on the host and in the container.

For some reason the @timestamp is neither UTC nor UTC+2, but unfortunately rather UTC+4. This happens regardless of `convert_timezone` being true or false. This option only affects `beat.timezone` being 00:00 or 02:00.

For the other log files, like apache2 and traefik this issue does not happen, because the log lines already contain the timezone information in the timestamps.

Does anyone have any idea about this issue or experienced the same? What am I doing wrong, besides unfortunately not using UTC for all log files and systems.

Thanks and best regards,  
Marc

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [April 16, 2019, 11:13am UTC](https://discuss.elastic.co/t/filebeat-system-and-iptables-module-timezone-offset-issue/176732/2 "2019-04-16T11:13:12Z")

</div>

Hi @mback2k,

After changing the value of `var.convert_timezone` you need to setup the pipelines again. You can do it by restarting filebeat with `filebeat.overwrite_pipelines: true` in the configuration. Take into account that this option can override other pipelines that you have manually setup. You may want to remove this option once the pipelines are setup as you expect.

You can check if the pipelines are being correctly configured by executing `GET _ingest/pipeline/filebeat-6.7.1-system-*` and checking that the date processors include the timezone option, like in:

```auto
        "date" : {
          "field" : "system.syslog.timestamp",
          "target_field" : "@timestamp",
          "formats" : [
            "MMM d HH:mm:ss",
            "MMM dd HH:mm:ss"
          ],
          "timezone" : "{{ beat.timezone }}",
          "ignore_failure" : true
        }

```

Regards,  
Jaime.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [April 16, 2019, 11:51am UTC](https://discuss.elastic.co/t/filebeat-system-and-iptables-module-timezone-offset-issue/176732/3 "2019-04-16T11:51:47Z")

</div>

There is an open issue to allow to use `filebeat setup --pipelines` to reconfigure the pipelines if a setting is changed: [https://github.com/elastic/beats/issues/9747](https://github.com/elastic/beats/issues/9747)

---

<div class="post-metadata">

**Author:** ![mback2k](https://avatars.discourse-cdn.com/v4/letter/m/53a042/32.png) [@mback2k](https://discuss.elastic.co/u/mback2k)\
**Post date:** [April 16, 2019, 7:35pm UTC](https://discuss.elastic.co/t/filebeat-system-and-iptables-module-timezone-offset-issue/176732/4 "2019-04-16T19:35:54Z")

</div>

Hi @jsoriano,

thank you very much. That seems to have solved the problem for me even though

```auto
"timezone" : "{{ beat.timezone }}",

```

was already included inside the pipeline. I could not spot any difference after overwriting the pipelines, but it started working anyway.

Best regards,  
Marc

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2019, 7:36pm UTC](https://discuss.elastic.co/t/filebeat-system-and-iptables-module-timezone-offset-issue/176732/5 "2019-05-14T19:36:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
