# Filebeat using Fortinet module TZ issue

**URL:** <https://discuss.elastic.co/t/filebeat-using-fortinet-module-tz-issue/251518>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [October 9, 2020, 1:23am UTC](https://discuss.elastic.co/t/filebeat-using-fortinet-module-tz-issue/251518 "2020-10-09T01:23:47Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Derick\_Jansen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/derick_jansen/32/71407_2.png) [@Derick\_Jansen](https://discuss.elastic.co/u/Derick_Jansen)\
**Post date:** [October 9, 2020, 1:23am UTC](https://discuss.elastic.co/t/filebeat-using-fortinet-module-tz-issue/251518/1 "2020-10-09T01:23:47Z")

</div>

Hi,

We are using Filebeat with the Fortinet module to ingest our FW logs via Syslog.  
Our Fortigates do not send timezone information in log entries.

The logs all have this format

```auto
<189>date=2020-10-09 time=14:06:56 devname=\" **** -fw1\"

```

Additionally, the FW is not set to GMT. The result is that all our events are logged 13 hours forward (We are at GMT+13)

Any way to explicitly set the timezone?

Thanks and regards!

---

<div class="post-metadata">

**Author:** ![Ameer\_Mukadam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ameer_mukadam/32/47196_2.png) [@Ameer\_Mukadam](https://discuss.elastic.co/u/Ameer_Mukadam)\
**Post date:** [October 11, 2020, 8:00am UTC](https://discuss.elastic.co/t/filebeat-using-fortinet-module-tz-issue/251518/2 "2020-10-11T08:00:57Z")

</div>

Glad I am not the only one I am also having the same issue. Our fortigates are set to use +5:30 and all my logs are +5:30 hr in the future.

---

<div class="post-metadata">

**Author:** ![Derick\_Jansen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/derick_jansen/32/71407_2.png) [@Derick\_Jansen](https://discuss.elastic.co/u/Derick_Jansen)\
**Post date:** [October 21, 2020, 11:06am UTC](https://discuss.elastic.co/t/filebeat-using-fortinet-module-tz-issue/251518/3 "2020-10-21T11:06:59Z")

</div>

Any help? If not setting the TZ explicitly, perhaps an ingest change?

---

<div class="post-metadata">

**Author:** ![Derick\_Jansen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/derick_jansen/32/71407_2.png) [@Derick\_Jansen](https://discuss.elastic.co/u/Derick_Jansen)\
**Post date:** [November 4, 2020, 4:18am UTC](https://discuss.elastic.co/t/filebeat-using-fortinet-module-tz-issue/251518/4 "2020-11-04T04:18:46Z")

</div>

I tried both File and Syslog ingestion. Problem exists in both cases. Upgraded to 7.9.3 but no difference.

---

<div class="post-metadata">

**Author:** ![Iker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iker/32/91708_2.png) [@Iker](https://discuss.elastic.co/u/Iker)\
**Post date:** [November 4, 2020, 5:09am UTC](https://discuss.elastic.co/t/filebeat-using-fortinet-module-tz-issue/251518/5 "2020-11-04T05:09:26Z")

</div>

If you are ingesting the logs through Logstash set the correct timezone pretty easy

```auto
    date {
        	match => ["@timestamp", "UNIX"]
        	timezone => "Pacific/Tongatapu"
     	        target => "@timestamp"
     }

```

If you are ingesting directly to ES, there are several options, using the option var.tz\_offset for the module, overwrite the event.timezone field with a processor or use a pipeline

> **[Fortinet module | Filebeat Reference \[7.9\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-fortinet.html#fortinet-settings)**

Be aware that in some versions (logver=60) Fortinet includes the timezone.

---

<div class="post-metadata">

**Author:** ![Derick\_Jansen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/derick_jansen/32/71407_2.png) [@Derick\_Jansen](https://discuss.elastic.co/u/Derick_Jansen)\
**Post date:** [November 5, 2020, 12:49am UTC](https://discuss.elastic.co/t/filebeat-using-fortinet-module-tz-issue/251518/6 "2020-11-05T00:49:53Z")

</div>

Hi @Iker

Thanks for the reply. We are ingesting directly but I will test via Logstash.

> [@Iker](#):
>
> var.tz\_offset

I did test var.tz\_offset and can confirm that it is only implemented for the **clientendpoint** fileset and not the **firewall** fileset.

---

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [November 5, 2020, 2:10am UTC](https://discuss.elastic.co/t/filebeat-using-fortinet-module-tz-issue/251518/7 "2020-11-05T02:10:31Z")

</div>

Looking at the pipeline 'filebeat-7.9.1-fortinet-firewall-pipeline' it looks like the timezone is read from the field: 'fortinet.firewall.tz'. You could try setting this field within Filebeat processor. This is an example value for what fortinet.firewall.tz is -0500.

Note: It appears that fortinet.firewall.tz is copied to event.timezone and then dropped within the pipeline, so if you're looking for the field value, look at event.timezone

---

<div class="post-metadata">

**Author:** ![Derick\_Jansen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/derick_jansen/32/71407_2.png) [@Derick\_Jansen](https://discuss.elastic.co/u/Derick_Jansen)\
**Post date:** [November 5, 2020, 7:01am UTC](https://discuss.elastic.co/t/filebeat-using-fortinet-module-tz-issue/251518/8 "2020-11-05T07:01:19Z")

</div>

Ok here are my findings

event.start - Nov 5, 2020 @ 19:20:00.000 - Correct  
event.timezone - +13:00 - Correct

@timestamp - Nov 6, 2020 @ 08:20:00.000 - Incorrect

In short, the timestamp is incorrect

---

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [November 5, 2020, 1:55pm UTC](https://discuss.elastic.co/t/filebeat-using-fortinet-module-tz-issue/251518/9 "2020-11-05T13:55:52Z")

</div>

According to the below part of the firewall pipeline, it should've set the @timestamp field to be correct.

```
{
"date": {
  "if": "ctx.fortinet?.firewall?.tz != null",
  "field": "_temp.time",
  "target_field": "@timestamp",
  "formats": [
    "yyyy-MM-dd HH:mm:ss",
    "yyyy-MM-dd HH:mm:ss Z",
    "yyyy-MM-dd HH:mm:ss z",
    "ISO8601"
  ],
  "timezone": "{{fortinet.firewall.tz}}"
}

```

Since the below is fairly similar to setting the event.start field.

```
{
"date": {
  "target_field": "event.start",
  "formats": [
    "UNIX"
  ],
  "timezone": "{{fortinet.firewall.tz}}",
  "if": "ctx.fortinet?.firewall?.tz != null && (ctx.fortinet?.firewall?.eventtime).length() <= 11",
  "field": "fortinet.firewall.eventtime"
}

```

What you can do if setting the fortinet.firewall.tz doesn't work, you can at the very end of the firewall pipeline, copy event.start field to @timestamp field. (Note: This might cause some issues as according to ECS they technically are two different values, but its a potential work around)

---

<div class="post-metadata">

**Author:** ![Derick\_Jansen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/derick_jansen/32/71407_2.png) [@Derick\_Jansen](https://discuss.elastic.co/u/Derick_Jansen)\
**Post date:** [November 6, 2020, 3:24am UTC](https://discuss.elastic.co/t/filebeat-using-fortinet-module-tz-issue/251518/10 "2020-11-06T03:24:27Z")

</div>

@Iker @BenB196@Ameer_Mukadam

Thanks a lot for all the help. I have now solved this issue.

**fortinet.yml**

```auto
- module: fortinet
  firewall:
    input:
      processors:
        - add_fields:
            target: ''
            fields:
              fortinet.firewall.tz: '+1300'
    enabled: true
    var.input: udp
    var.syslog_port: 5514

```

I also tried add\_locale processor as below.

```auto
processors:
  - add_locale: ~

```

This would be preferable as daylight saving changes the offset but add\_locale uses "+13:00" as the format which the pipeline does not support.

I might use the script processor to modify the add\_local value.

---

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [November 6, 2020, 1:31pm UTC](https://discuss.elastic.co/t/filebeat-using-fortinet-module-tz-issue/251518/11 "2020-11-06T13:31:57Z")

</div>

Another thing to potentially note. You might want to try setting the Canonical ID for the Timezone. Even though my original example was the standard offset, I've realized that the Canonical ID should also work for the fortinet.firewall.tz. This is because the pipeline is what is using the timezone, and the date processor should accept the Canonical ID as well as the standard offset, which should help overcome your DST issue.

---

<div class="post-metadata">

**Author:** ![Ameer\_Mukadam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ameer_mukadam/32/47196_2.png) [@Ameer\_Mukadam](https://discuss.elastic.co/u/Ameer_Mukadam)\
**Post date:** [November 9, 2020, 4:54am UTC](https://discuss.elastic.co/t/filebeat-using-fortinet-module-tz-issue/251518/12 "2020-11-09T04:54:51Z")

</div>

> [@Derick\_Jansen](#):
>
> Nov 6, 2020 @ 08:20:00.000

Thank you very very much this was so frustrating and even the support couldn't help me in this, you fixed it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 7, 2020, 6:55am UTC](https://discuss.elastic.co/t/filebeat-using-fortinet-module-tz-issue/251518/13 "2020-12-07T06:55:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
