I have several log event with GMT time period. Initially we are converting the event time while inserting in elasticsearch because the log file is creating in PST server but event time is in GMT. we are using the kibana in PST region and kibana showing the data till 5 PM PST in discover and this scenario is happening only when i try to apply the below timezone in logstash. Please find the below image.
Reason for conversion,
Since the server is in PST time region elasticsearch trying to convert the PST to GMT, but in my case the log events are in GMT time. To avoid conflict or mismatch of event we preferred the below conversion process.
match => ["iis_eventDate", "YYYY-MM-dd HH:mm:ss" ]
target => ["iis_eventDate"]
timezone => ['Etc/GMT']