# \*I am working with wireshark pcaps inside of SO kibana and hunt. Seems like the timestamps do not match?

**URL:** <https://discuss.elastic.co/t/i-am-working-with-wireshark-pcaps-inside-of-so-kibana-and-hunt-seems-like-the-timestamps-do-not-match/338612>\
**Category:** Kibana\
**Created:** [July 18, 2023, 12:04am UTC](https://discuss.elastic.co/t/i-am-working-with-wireshark-pcaps-inside-of-so-kibana-and-hunt-seems-like-the-timestamps-do-not-match/338612 "2023-07-18T00:04:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![iqworks](https://avatars.discourse-cdn.com/v4/letter/i/a9a28c/32.png) [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Post date:** [July 18, 2023, 12:04am UTC](https://discuss.elastic.co/t/i-am-working-with-wireshark-pcaps-inside-of-so-kibana-and-hunt-seems-like-the-timestamps-do-not-match/338612/1 "2023-07-18T00:04:34Z")

</div>

Hi, I am using windows 11, SO, winlogbeat and logstash  
output.logstash:

# The Logstash hosts

```
hosts: ["192.168.1.226:5044"]

```

I have saved a wireshark session as a pcap. I moved the pcap from my windows 10 machine with winSCP. I ran  
So-import-pcap and got the url. I went into kibana and hunt and changed the from and to times to match the from  
To date/time in the wireshark pcap. But when I try to match up the timestamps between wireshark and  
Kibana or hunt, I see the src ip and the dst ip’s that match, so I am wondering if there is a way to send  
Pcaps from winSCP to SO with the same timestamps?  
Thanks for any advice or suggestions.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [July 18, 2023, 3:09pm UTC](https://discuss.elastic.co/t/i-am-working-with-wireshark-pcaps-inside-of-so-kibana-and-hunt-seems-like-the-timestamps-do-not-match/338612/2 "2023-07-18T15:09:11Z")

</div>

Packetbeat can also get pcap data, so that will be the most accurate one to use with Kibana.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [July 18, 2023, 3:32pm UTC](https://discuss.elastic.co/t/i-am-working-with-wireshark-pcaps-inside-of-so-kibana-and-hunt-seems-like-the-timestamps-do-not-match/338612/3 "2023-07-18T15:32:27Z")

</div>

I'm not sure am I get you, but will give it try my version.  
If you have logs which has been read by an app, for instance beats, a message must have a `@timestamp` field when it enters LS, otherwise LS will create the `@timestamp` field with the current time of LS host. [FB documentation](https://www.elastic.co/guide/en/beats/filebeat/current/processor-timestamp.html)  
Always you can use the date plugin which has default target "@timestamp"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 15, 2023, 3:33pm UTC](https://discuss.elastic.co/t/i-am-working-with-wireshark-pcaps-inside-of-so-kibana-and-hunt-seems-like-the-timestamps-do-not-match/338612/4 "2023-08-15T15:33:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
