# How to set @timestamp timezone?

**URL:** <https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401>\
**Category:** Logstash\
**Created:** [September 1, 2015, 4:26am UTC](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401 "2015-09-01T04:26:15Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![z\_w\_w1981](https://avatars.discourse-cdn.com/v4/letter/z/41988e/32.png) [@z\_w\_w1981](https://discuss.elastic.co/u/z_w_w1981)\
**Post date:** [September 1, 2015, 4:26am UTC](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401/1 "2015-09-01T04:26:16Z")

</div>

Hi,

I found that the @timestamp always show UTC time,  
My date filter is:  
date {  
match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]  
timezone =\> "Asia/Shanghai"  
}

after process the timestamp is:  
"@timestamp" =\> "2015-08-27T03:07:56.000Z",  
"timestamp" =\> "27/Aug/2015:11:07:56 +0800",

The timezone is different. I have searched in the website and use: code =\> "event['@timestamp'] = event['@timestamp'].localtime("+08:00")", but ruby doesn't support localtime method.

Questions:

1. How can I change the @timestamp match my timestamp?
2. Can I set timezone in the Kibana?

Thanks!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 1, 2015, 5:46am UTC](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401/2 "2015-09-01T05:46:17Z")

</div>

> 1. How can I change the @timestamp match my timestamp?

Please don't. Store the timestamps in UTC and leave the timezone adjustments to presentation layers. You are spending time on solving a problem that doesn't exist.

> 1. Can I set timezone in the Kibana?

I believe Kibana always adjusts the UTC time to the browser's timezone. In Kibana 3 this is optional but in Kibana 4 I don't think you can turn it off.

---

<div class="post-metadata">

**Author:** ![z\_w\_w1981](https://avatars.discourse-cdn.com/v4/letter/z/41988e/32.png) [@z\_w\_w1981](https://discuss.elastic.co/u/z_w_w1981)\
**Post date:** [September 1, 2015, 6:04am UTC](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401/3 "2015-09-01T06:04:32Z")

</div>

Thanks for reply!

But In Kibana, how can I calculate values (e.g daily count) using my local timezone? Because Kibana uses @timestamp to do aggregation which is UTC time.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 1, 2015, 6:16am UTC](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401/4 "2015-09-01T06:16:41Z")

</div>

It uses UTC but if you ask for $today then it will only show the 24 hours from $now to $now-24hr relative to your TZ, not UTC absolute.

---

<div class="post-metadata">

**Author:** ![z\_w\_w1981](https://avatars.discourse-cdn.com/v4/letter/z/41988e/32.png) [@z\_w\_w1981](https://discuss.elastic.co/u/z_w_w1981)\
**Post date:** [September 10, 2015, 8:23am UTC](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401/5 "2015-09-10T08:23:18Z")

</div>

Hi,

I have one more question about timestamp:

1. Logstash generates indexes based on @timestamp with UTC time, if I want to get documents from  
2015-09-01 to 2015-09-02 with my timezone, I need to search indexes logstash-2015.08.31 and  
logstash-2015.09.01, if I can change the @timestamp to my timezone direct, I think I can directly  
search the index logstash-2015.09.01. Correct?
2. I use the filter:  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}"}  
}  
can I parse the timestamp to add fields "year", "month", "day"?  
e.g.: 20/Aug/2015:07:06:25 +0800  
to : "year" =\> "2015" "month"=\>"2015-08" "day" =\> "2015-08-20"

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 10, 2015, 8:32am UTC](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401/6 "2015-09-10T08:32:27Z")

</div>

1. Yes.
2. Sure, you can have an additional grok filter that extracts those fields from the `timestamp` that's produced by the COMBINEDAPACHELOG pattern. But why would you want to do that? A range query against the `@timestamp` field is simple and fast.

---

<div class="post-metadata">

**Author:** ![z\_w\_w1981](https://avatars.discourse-cdn.com/v4/letter/z/41988e/32.png) [@z\_w\_w1981](https://discuss.elastic.co/u/z_w_w1981)\
**Post date:** [September 10, 2015, 8:40am UTC](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401/7 "2015-09-10T08:40:50Z")

</div>

1. How can I change the @timestamp, from your first reply it looks like I can't change it...
2. I want to calculate some fields count by daily, weekly, monthly. currently if I calculate 10 days count, I should use range query to run 10 times, I think if I have a day field to aggregate, it should be faster.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 10, 2015, 9:02am UTC](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401/8 "2015-09-10T09:02:21Z")

</div>

1. Correct, it's not configurable and as we've explained you really shouldn't touch it either. However, you can trick Logstash by setting the timezone of the date filter to UTC, thereby disabling the timezone adjustment when parsing the date.
2. Elasticsearch can do that for you. Just use a [date histogram aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-datehistogram-aggregation.html). But I guess Kibana currently isn't capable of passing the timezone parameter.

---

<div class="post-metadata">

**Author:** ![z\_w\_w1981](https://avatars.discourse-cdn.com/v4/letter/z/41988e/32.png) [@z\_w\_w1981](https://discuss.elastic.co/u/z_w_w1981)\
**Post date:** [September 10, 2015, 10:01am UTC](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401/9 "2015-09-10T10:01:03Z")

</div>

I can't trick the Logstash by set the timezone to "UTC", my message's timestamp is "[20/Aug/2015:21:06:25 +0800]", date filter is  
date {  
match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]  
timezone =\> "UTC"  
}  
what's wrong with it?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 10, 2015, 10:58am UTC](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401/10 "2015-09-10T10:58:09Z")

</div>

You probably need to omit the "Z" token in the pattern. Try this:

```
date {
  match => ["timestamp" , "dd/MMM/yyyy:HH:mm:ss +0800"]
  timezone => "UTC"
}

```

If that works, consider removing "+0800" from the pattern _and_ from the `timestamp` field.

---

<div class="post-metadata">

**Author:** ![z\_w\_w1981](https://avatars.discourse-cdn.com/v4/letter/z/41988e/32.png) [@z\_w\_w1981](https://discuss.elastic.co/u/z_w_w1981)\
**Post date:** [September 10, 2015, 12:39pm UTC](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401/11 "2015-09-10T12:39:12Z")

</div>

"+0800" works fine, just remove it from the date pattern will cause error, I think remove it from timestamp field needs change the COMBINEDAPACHELOG pattern, it's a little bit complex.

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 10, 2015, 1:46pm UTC](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401/12 "2015-09-10T13:46:27Z")

</div>

You can change your initial grok expression or you can delete the timezone token from the resulting `timestamp` field using the mutate filter's gsub parameter.

---

<div class="post-metadata">

**Author:** ![z\_w\_w1981](https://avatars.discourse-cdn.com/v4/letter/z/41988e/32.png) [@z\_w\_w1981](https://discuss.elastic.co/u/z_w_w1981)\
**Post date:** [September 11, 2015, 4:10am UTC](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401/13 "2015-09-11T04:10:08Z")

</div>

I use the "COMBINEDAPACHELOG" pattern, in the grok-patterns file, I see "COMBINEDAPACHELOG" uses "COMMONAPACHELOG" which include "HTTPDATE",  
so I want to get "year" as a new field, my grok filter is:  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}"}  
add\_field =\> {"year" =\> "%{YEAR}"}  
}

but %{YEAR} doesn't work, how can I get the "year" field?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 11, 2015, 5:42am UTC](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401/14 "2015-09-11T05:42:01Z")

</div>

I suggest you add a second grok filter to extract the year from the newly extracted timestamp:

```
grok {
  match => ["timestamp", "^%{MONTHDAY}/%{MONTH}/%{YEAR:year}"]
}
```

---

<div class="post-metadata">

**Author:** ![z\_w\_w1981](https://avatars.discourse-cdn.com/v4/letter/z/41988e/32.png) [@z\_w\_w1981](https://discuss.elastic.co/u/z_w_w1981)\
**Post date:** [September 11, 2015, 6:04am UTC](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401/15 "2015-09-11T06:04:59Z")

</div>

It works, Thank you very much for your patience!

---

<div class="post-metadata">

**Author:** ![jack6liu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack6liu/32/6577_2.png) [@jack6liu](https://discuss.elastic.co/u/jack6liu)\
**Post date:** [December 11, 2015, 6:52am UTC](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401/16 "2015-12-11T06:52:56Z")

</div>

A newbie to ELK stack. And met such issue also.

From a system admin/ user view, I should say this is a workaroud, and everything should goes perfect if the logstash just add the supporting to customize the timezone .

Why not add this simple feature? But specify such a complex workaround??

---

<div class="post-metadata">

**Author:** ![jarvan4dev](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jarvan4dev](https://discuss.elastic.co/u/jarvan4dev)\
**Post date:** [January 15, 2016, 2:58pm UTC](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401/17 "2016-01-15T14:58:21Z")

</div>

Hi, magnusbaeck

if I just want to change the @timestamp field, what should I do? the following is my log format:  
2016-01-15 09:33:23,650 INFO [127.0.0.1:57799 http-bio-8080-exec-10] com.ins.car.controller.CarOrderController.getInsResult(CarOrderController.java:62) - 2016-01-15 17:33:23,458 getInsResultServlet {....}

as you see, there is two times, 2016-01-15 09:33:23,650 and 2016-01-15 17:33:23,458, the first one is %{+yyyy-MM-dd HH:mm:ss,SSS}, the second one comes from the source message

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 17, 2016, 4:29pm UTC](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401/18 "2016-01-17T16:29:08Z")

</div>

@jarvan4dev—please start a new thread for your question.

---

<div class="post-metadata">

**Author:** ![trondhindenes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/trondhindenes/32/10534_2.png) [@trondhindenes](https://discuss.elastic.co/u/trondhindenes)\
**Post date:** [September 1, 2016, 1:22pm UTC](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401/19 "2016-09-01T13:22:46Z")

</div>

For ref, Kibana 4.5 supports changing this in settings--\>advanced.

---

<div class="post-metadata">

**Author:** ![navien](https://avatars.discourse-cdn.com/v4/letter/n/8e8cbc/32.png) [@navien](https://discuss.elastic.co/u/navien)\
**Post date:** [September 13, 2016, 11:41am UTC](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401/20 "2016-09-13T11:41:29Z")

</div>

> [@magnusbaeck](#):
>
> However, you can trick Logstash by setting the timezone of the date filter to UTC, thereby disabling the timezone adjustment when parsing the date.

Hello @magnusbaeck,  
Thanks so much for your insights on handling the timstamp conversion in logstash. I tried your suggestions on tricking the logstash using date filter to UTC but it does not seem to work. My need is to have logstash write the output from DB2 to a flat file without changing the original timezone of the data. So, i want to avoid logstash (2.3.4) having to convert my date fields to UTC.

format of my raw data from db for field say RECENT\_TS is 2016-09-12 14:08:13.355243 and is in MST timezone.

filter {  
date {  
match =\> ["RECENT\_TS", "ISO8601"]  
locale =\> "en"  
timezone =\> "UTC"  
}  
}  
when i used this date filter and executed it, i got the following error  
Failed parsing date from field {:field=\>"RECENT\_TS", :value=\>"2016-09-12T17:43:12.148Z", :exception=\>"cannot convert instance of class org.jruby.RubyObject to class java.lang.String", :config\_parsers=\>"ISO8601", :config\_locale=\>"en", :level=\>:warn}

so I included a mutate to convert to string before doing a date filter like below

filter {  
mutate {  
convert =\> ["RECENT\_TS" , "string"]  
}  
date {  
match =\> ["RECENT\_TS", "ISO8601"]  
locale =\> "en"  
timezone =\> "UTC"  
}  
}

Now i do not have any errors but my original problem is still not solved

logstash output : "RECENT\_TS":"2016-09-12T22:00:36.403Z"  
DB input for RECENT\_TS field : 2016-09-12 15:00:36.403977

I tried giving different canonical ID values in timezone param in date filter but doesnt seemt to reflect in logstash output - am i missing something here ? Your help is appreciated !

[Next page](https://discuss.elastic.co/t/how-to-set-timestamp-timezone/28401.md?page=2)
