# Filebeat system module auth log timezone conversion problem

**URL:** <https://discuss.elastic.co/t/filebeat-system-module-auth-log-timezone-conversion-problem/140192>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 16, 2018, 4:25pm UTC](https://discuss.elastic.co/t/filebeat-system-module-auth-log-timezone-conversion-problem/140192 "2018-07-16T16:25:33Z")\
**Posts on this page:** 1\
**Showing post:** 7

<div class="post-metadata">

**Author:** ![Ray\_Frush](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ray_frush/32/46306_2.png) [@Ray\_Frush](https://discuss.elastic.co/u/Ray_Frush)\
**Post date:** [July 19, 2018, 3:01pm UTC](https://discuss.elastic.co/t/filebeat-system-module-auth-log-timezone-conversion-problem/140192/7 "2018-07-19T15:01:05Z")

</div>

Andrew-

Thanks for the pointer. That got it!

curl -XGET '[http://localhost:9200/\_ingest/pipeline](http://localhost:9200/_ingest/pipeline)'  
(shows all of the pipelines in place)  
curl -XDELETE '[http://localhost:9200/\_ingest/pipeline/filebeat-6.3.1-system-auth-pipeline](http://localhost:9200/_ingest/pipeline/filebeat-6.3.1-system-auth-pipeline)'  
curl -XDELETE '[http://localhost:9200/\_ingest/pipeline/filebeat-6.3.1-system-syslog-pipeline](http://localhost:9200/_ingest/pipeline/filebeat-6.3.1-system-syslog-pipeline)'  
( I probably didn't need to remove both of the pipelines, but just to be sure)

curl -XGET '[http://localhost:9200/\_ingest/pipeline](http://localhost:9200/_ingest/pipeline)'  
( showed a much shorter list)

I'm a little surprised that filebeat doesn't (or can't) update an existing pipeline when parameters are updated in the Filebeat config. Is there a reason for that?

--  
Ray Frush  
Colorado State University

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-system-module-auth-log-timezone-conversion-problem/140192)._
