# Kibana adds 2 hours to timestamp

**URL:** <https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731>\
**Category:** Kibana\
**Created:** [October 24, 2016, 10:11am UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731 "2016-10-24T10:11:12Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![trenzalore](https://avatars.discourse-cdn.com/v4/letter/t/ac91a4/32.png) [@trenzalore](https://discuss.elastic.co/u/trenzalore)\
**Post date:** [October 24, 2016, 10:11am UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731/1 "2016-10-24T10:11:12Z")

</div>

Hi !

I know that this question comes back often but I didn't find a good answer for my problem.

So I set up a cluster of 3 servers: Two are made up with the docker image sebp/elk and the kibana server is installed with the elastic repo.

Everything work fine except the timestamp shown in kibana.  
I change the localtime in the docker containers and reboot them but nothing changed.

My logstash confs do not include any date parsing and worked on a test node.

Thanks !

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 24, 2016, 10:55am UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731/2 "2016-10-24T10:55:12Z")

</div>

The timestamps are supposed to be stored in UTC in Elasticsearch and the Kibana web app (i.e. your browser) adjusts the timestamps to local time. The latter behavior is configurable via Settings -\> Advanced.

---

<div class="post-metadata">

**Author:** ![trenzalore](https://avatars.discourse-cdn.com/v4/letter/t/ac91a4/32.png) [@trenzalore](https://discuss.elastic.co/u/trenzalore)\
**Post date:** [October 24, 2016, 11:02am UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731/3 "2016-10-24T11:02:34Z")

</div>

I adjusted the time to my timezone but it still don't work ! the @timestamp still has 2 more hours than the time in the log.

![](https://us1.discourse-cdn.com/elastic/original/2X/b/bedd54a8f16610814e71dee2c675d925c188e9b6.png)

EDIT: by puting Etc/GMT+0 It works but Europe/Paris doesn't have the good time. If I want to visualize the last 15 minutes, I see the last 15 minutes but 2 hours ago..

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 24, 2016, 11:27am UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731/4 "2016-10-24T11:27:51Z")

</div>

Is "Oct 24 13:01:59" in UTC+2? What's stored in ES for that event, i.e. what's the raw `@timestamp` value? You can find it in Kibana on the JSON tab if you expand the message in the Discover view.

---

<div class="post-metadata">

**Author:** ![trenzalore](https://avatars.discourse-cdn.com/v4/letter/t/ac91a4/32.png) [@trenzalore](https://discuss.elastic.co/u/trenzalore)\
**Post date:** [October 24, 2016, 11:31am UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731/5 "2016-10-24T11:31:27Z")

</div>

France is in UTC+1.  
Here's the value: 1477315740000 (well that's not the value of 13:01:59 but more of 13:29:00)

I put Kibane in gmt + 0.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 24, 2016, 11:42am UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731/6 "2016-10-24T11:42:59Z")

</div>

> France is in UTC+1.

No, not until Oct 30 when daylight savings time ends. Right now you're UTC+2.

> Here's the value: 1477315740000

That's not what the `@timestamp` fields looks like. Where did you get that from? Anyway, 1477315740000 is 2016-10-24 13:29:00 UTC. Your log files are UTC+2 so if they contain 13:29:00 the value stored in ES should be 11:29:00.

---

<div class="post-metadata">

**Author:** ![trenzalore](https://avatars.discourse-cdn.com/v4/letter/t/ac91a4/32.png) [@trenzalore](https://discuss.elastic.co/u/trenzalore)\
**Post date:** [October 24, 2016, 11:46am UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731/7 "2016-10-24T11:46:06Z")

</div>

Yes you right, I just copied-pasted google.

Well this is what I get when I expand a message and click on JSON and search for the @timestamp field.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 24, 2016, 11:51am UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731/8 "2016-10-24T11:51:31Z")

</div>

> Well this is what I get when I expand a message and click on JSON and search for the @timestamp field.

Oh, you copied this part:

```plaintext
  "fields": {
    "@timestamp": [
      1477306667396
    ]
  },

```

This is the part I'm interested in:

```
    "@timestamp": "2016-10-24T10:57:47.396Z",

```

---

<div class="post-metadata">

**Author:** ![trenzalore](https://avatars.discourse-cdn.com/v4/letter/t/ac91a4/32.png) [@trenzalore](https://discuss.elastic.co/u/trenzalore)\
**Post date:** [October 24, 2016, 11:53am UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731/9 "2016-10-24T11:53:09Z")

</div>

So:  
`"@timestamp": "2016-10-24T13:36:20.000Z"`

And:

```
  "fields": {
    "@timestamp": [
      1477316180000
    ]
  }
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 24, 2016, 11:56am UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731/10 "2016-10-24T11:56:25Z")

</div>

Okay. Your date filter is broken since it doesn't adjust the timezone of the parsed timestamp to UTC. The filter defaults to the system's timezone, but you can override that with the date filter's `timezone`. In your case I suppose `timezone => "Europe/Paris"` would be correct.

---

<div class="post-metadata">

**Author:** ![trenzalore](https://avatars.discourse-cdn.com/v4/letter/t/ac91a4/32.png) [@trenzalore](https://discuss.elastic.co/u/trenzalore)\
**Post date:** [October 24, 2016, 12:00pm UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731/11 "2016-10-24T12:00:25Z")

</div>

Here's what happens when I set Europe/Paris:

![](https://us1.discourse-cdn.com/elastic/original/2X/9/9a22a819c9419eed749aea315528c4dc547cf988.png)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 24, 2016, 1:05pm UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731/12 "2016-10-24T13:05:55Z")

</div>

What do your filters look like?

---

<div class="post-metadata">

**Author:** ![trenzalore](https://avatars.discourse-cdn.com/v4/letter/t/ac91a4/32.png) [@trenzalore](https://discuss.elastic.co/u/trenzalore)\
**Post date:** [October 24, 2016, 1:10pm UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731/13 "2016-10-24T13:10:33Z")

</div>

This is the only conf I put in the logstash conf.d directory:

> <https://gist.github.com/newclem/974794b23c8cd5ff51514cd28af05c0f>

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 24, 2016, 1:15pm UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731/14 "2016-10-24T13:15:19Z")

</div>

This is what I get when trying parts of your config, and I'm also in UTC+2:

```nohighlight
$ cat test.config 
input { stdin { } }
output { stdout { codec => rubydebug } }
filter {
  date {
    match => ["message", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
  }
}
$ echo 'Oct 24 11:57:51' | /opt/logstash/bin/logstash -f test.config
Settings: Default pipeline workers: 8
Pipeline main started
{
       "message" => "Oct 24 11:57:51",
      "@version" => "1",
    "@timestamp" => "2016-10-24T09:57:51.000Z",
          "host" => "lnxolofon"
}
Pipeline main has been shutdown
stopping pipeline {:id=>"main"}

```

Are you getting something else if you try the same thing?

---

<div class="post-metadata">

**Author:** ![trenzalore](https://avatars.discourse-cdn.com/v4/letter/t/ac91a4/32.png) [@trenzalore](https://discuss.elastic.co/u/trenzalore)\
**Post date:** [October 24, 2016, 1:18pm UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731/15 "2016-10-24T13:18:36Z")

</div>

Not at all:

```
root@e3df854be0f8:~# echo 'Oct 24 11:57:51' | /opt/logstash/bin/logstash -f test.config
Settings: Default pipeline workers: 2
Pipeline main started
{
       "message" => "Oct 24 11:57:51",
      "@version" => "1",
    "@timestamp" => "2016-10-24T11:57:51.000Z",
          "host" => "e3df854be0f8"
}
Pipeline main has been shutdown
stopping pipeline {:id=>"main"}

```

EDIT: the localtime file used on my docker containers are Europe/Paris, maybe that's why we don't have the same output

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 24, 2016, 1:43pm UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731/16 "2016-10-24T13:43:56Z")

</div>

And this doesn't change even if you add `timezone => "Europe/Paris"` in your date filter?

---

<div class="post-metadata">

**Author:** ![trenzalore](https://avatars.discourse-cdn.com/v4/letter/t/ac91a4/32.png) [@trenzalore](https://discuss.elastic.co/u/trenzalore)\
**Post date:** [October 24, 2016, 1:52pm UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731/17 "2016-10-24T13:52:58Z")

</div>

Not at all. I think that it's a problem with the timezone from the docker container.  
When I restart each container and watch logstash.log, the date printed is UTC and not UTC+2.  
I thought I changed the hour from the docker containers..

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 24, 2016, 1:55pm UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731/18 "2016-10-24T13:55:03Z")

</div>

But when setting the `timezone` option the environment's timezone is overridden so it doesn't matter that the container runs UTC. Are the timezone files available inside the container? If it's a Debian-based container you should have the tzdata package installed with files in /usr/share/zoneinfo.

---

<div class="post-metadata">

**Author:** ![trenzalore](https://avatars.discourse-cdn.com/v4/letter/t/ac91a4/32.png) [@trenzalore](https://discuss.elastic.co/u/trenzalore)\
**Post date:** [October 24, 2016, 1:58pm UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731/19 "2016-10-24T13:58:29Z")

</div>

yes it's based on debian.  
What I've done:  
rm /etc/timezone  
ln -s /usr/share/zoneinfo/Europe/Paris /etc/timezone  
dpkg-reconfigure -f noninteractive tzdata

EDIT: IT WORKS ! I deleted the index and everything work fine ! Thank you for your time !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:35pm UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731/20 "2017-07-06T13:35:55Z")

</div>


