# Filebeat TimeZone Issue

**URL:** <https://discuss.elastic.co/t/filebeat-timezone-issue/192999>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 30, 2019, 10:18pm UTC](https://discuss.elastic.co/t/filebeat-timezone-issue/192999 "2019-07-30T22:18:15Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![adwaitjoshi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adwaitjoshi/32/35098_2.png) [@adwaitjoshi](https://discuss.elastic.co/u/adwaitjoshi)\
**Post date:** [July 30, 2019, 10:18pm UTC](https://discuss.elastic.co/t/filebeat-timezone-issue/192999/1 "2019-07-30T22:18:15Z")

</div>

I am using version 7.2.0 and have system module enabled. What I am seeing is that when an event occures lets say at 6PM. When this event is sent to elasticsearch it assumes this is UTC and when opened in browser adjusts it to 2PM. However the event is really 6PM EST.

I see that there is a configuration value

processors:

- add\_locale: ~

However that seems to be doing nothing. How do I configure filebeat to pickup the value from the system config? And then keep it the same?

---

<div class="post-metadata">

**Author:** ![cosloli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cosloli/32/51115_2.png) [@cosloli](https://discuss.elastic.co/u/cosloli)\
**Post date:** [July 31, 2019, 4:46am UTC](https://discuss.elastic.co/t/filebeat-timezone-issue/192999/2 "2019-07-31T04:46:08Z")

</div>

Me too. I have the same problem as yours. This is a real bug and the Elastic team hasn't solve it yet.

See this thread: [[Still Not Solved!] Filebeat cannot recognize timezone in syslog](https://discuss.elastic.co/t/still-not-solved-filebeat-cannot-recognize-timezone-in-syslog/192661)

---

<div class="post-metadata">

**Author:** ![adwaitjoshi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adwaitjoshi/32/35098_2.png) [@adwaitjoshi](https://discuss.elastic.co/u/adwaitjoshi)\
**Post date:** [July 31, 2019, 11:57am UTC](https://discuss.elastic.co/t/filebeat-timezone-issue/192999/3 "2019-07-31T11:57:53Z")

</div>

So there is no solution? I have set the convert time stamp to true in System module. I dont use logstash so filebeat sends directly to Kibana and its not converting the timestamp.

---

<div class="post-metadata">

**Author:** ![ShaqFanClub](https://avatars.discourse-cdn.com/v4/letter/s/b19c9b/32.png) [@ShaqFanClub](https://discuss.elastic.co/u/ShaqFanClub)\
**Post date:** [July 31, 2019, 1:14pm UTC](https://discuss.elastic.co/t/filebeat-timezone-issue/192999/4 "2019-07-31T13:14:52Z")

</div>

I had this problem with a different module. My solution only worked for me because the logs came through in real time. If you need an older timestamp, this probably won't work.

My current "workaround" is removing any timestamp-related modification in the ingest pipeline:

- /usr/share/filebeat/module/system/(auth or syslog)/ingest/pipeline.json on Linux  
\*\*\*Not sure where this lives on Windows

After editing this file, you have to delete the old ingest pipeline (the dev tools command will look something like this):

- DELETE \_ingest/pipeline/filebeat-7.2.0-system-\*

Once the old pipeline is deleted, restart filebeat. The new pipeline will be registered and the @timestamp should be current.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 28, 2019, 1:24pm UTC](https://discuss.elastic.co/t/filebeat-timezone-issue/192999/5 "2019-08-28T13:24:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
