# Kibana incorrect time shown

**URL:** <https://discuss.elastic.co/t/kibana-incorrect-time-shown/190521>\
**Category:** Kibana\
**Created:** [July 15, 2019, 11:48am UTC](https://discuss.elastic.co/t/kibana-incorrect-time-shown/190521 "2019-07-15T11:48:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![nfccas](https://avatars.discourse-cdn.com/v4/letter/n/a3d4f5/32.png) [@nfccas](https://discuss.elastic.co/u/nfccas)\
**Post date:** [July 15, 2019, 11:48am UTC](https://discuss.elastic.co/t/kibana-incorrect-time-shown/190521/1 "2019-07-15T11:48:51Z")

</div>

Hello,

I'm having a long fight with Kibana/Logstash (7.2.0 and 7.0.0) due to this "issue" that occurs with other people too.

After reading other topics/discussions i've done some corrections to my Logstash configuration file. As you can see below, i parse the _timestamp_ field as ISO 8601 (\*1) and i set the _timezone_ to "Europe/Lisbon". I set this field because i read in a discussion that this can handle the Daylight Saving. So, in the time of the writing Portugal is UTC+1H.

(\*1) My Log4J2 configuration file has the following: _KeyValuePair key="timestamp" value="$${date:yyyy-MM-dd'T'HH:mm:ss.SSS'Z'}"_

> ```
> input {
> beats {
> port => "5044"
> }
> }
> 
> filter {
> json {
> source => "message"
> }
> json {
> source => "message"
> skip_on_invalid_json => true
> }
> date {
> match => ["timestamp", "ISO8601"]
> timezone => "Europe/Lisbon"
> }
> }
> 
> output {
> elasticsearch {
> hosts => ["localhost:9200"]
> index => "my-custom-index"
> }
> }
> 
> ```

Unfortunately i've always get my logs 1 hour ahead shown on timeline.  
If i change settings on _Management \> Advanced settings \> dateFormat:tz_ between "Portugal", "Europe/Lisbon", "Browser" or "UTC", i don't see any changes.

I also changed my laptop configurations for date & time to disable Daylight Saving, but with no success on Kibana.

I see in Kibana that the fetched data (_log \> Expanded document \> JSON_) is correct, so i'm assuming that this is a Kibana thing.

Am i missing something?

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [July 15, 2019, 12:09pm UTC](https://discuss.elastic.co/t/kibana-incorrect-time-shown/190521/2 "2019-07-15T12:09:09Z")

</div>

The Kibana timeline is controlled by the time field chosen when you define the index pattern to Kibana, usually @timestamp. In the expanded document, compare the time in "message" with @timestamp. Compare those fields to verify the date filter is working.

If not set, @timestamp defaults to ingest time.

I don't understand why you are calling the json filter twice with source =\> message, I think the second just overwrites what the first has done, but I don't think it's related to the time problem.

---

<div class="post-metadata">

**Author:** ![nfccas](https://avatars.discourse-cdn.com/v4/letter/n/a3d4f5/32.png) [@nfccas](https://discuss.elastic.co/u/nfccas)\
**Post date:** [July 15, 2019, 4:09pm UTC](https://discuss.elastic.co/t/kibana-incorrect-time-shown/190521/3 "2019-07-15T16:09:10Z")

</div>

Hello Len,

Thank you for the reply!

I'm overriding the _@timestamp_ and that was achieved easily a long ago. The timestamp in Kibana is equal to the one in my application console (in miliseconds), as the order of the logs.

The fact that i'm calling the JSON filter plugin twice is because i have a nested _message_ field inside the first, so the Logstash will "chain" the filters and index all the json items to the event document. I avoided to use adicional adapters in Log4J2 and add data to MDC. It's awesome!

And i don't think too that it's related to the problem, as i already explained above, i see the correct timestamps.

---

<div class="post-metadata">

**Author:** ![nfccas](https://avatars.discourse-cdn.com/v4/letter/n/a3d4f5/32.png) [@nfccas](https://discuss.elastic.co/u/nfccas)\
**Post date:** [July 16, 2019, 10:10am UTC](https://discuss.elastic.co/t/kibana-incorrect-time-shown/190521/4 "2019-07-16T10:10:06Z")

</div>

Hi,

I finally managed to get this working!

The problem is that i was sending the wrong datetime data to ELK.

As i said in my first topic the format of my application is the following:

> yyyy-MM-dd'T'HH:mm:ss.SSS'Z'

But this is wrong because it's the format of UTC (ISO8601).  
From my application i need to send the information of my timezone (or offset).

### So what i did was:

1. Remove _datetime_ field from my JSONLayout (log4j2)
2. Use the UNIX timestamp field already attached by log4j2 that is called _timeMillis_
3. In my logstash configuration file i changed the Date filter to the following:

> date {  
> match =\> ["timeMillis", "UNIX\_MS"]  
> timezone =\> "Europe/Lisbon"  
> }

This configuration means that i'm receaving a timestamp from Lisbon, so Logstash (or ES) will convert it to UTC applying Lisbon offset. In Kibana the event is correct now leaving _dateFormat:tz_ as default.

Probably i have to do some changes if i'm sending events from different machines in another timezone.

I hope this help someone else.

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [July 16, 2019, 1:02pm UTC](https://discuss.elastic.co/t/kibana-incorrect-time-shown/190521/5 "2019-07-16T13:02:39Z")

</div>

Glad that you posted the solution as well. Hope it helps the community at large.

Thanki  
Rashmi

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 13, 2019, 1:02pm UTC](https://discuss.elastic.co/t/kibana-incorrect-time-shown/190521/6 "2019-08-13T13:02:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
