# Kibana Timezone settings

**URL:** <https://discuss.elastic.co/t/kibana-timezone-settings/71793>\
**Category:** Logstash\
**Created:** [January 16, 2017, 11:27pm UTC](https://discuss.elastic.co/t/kibana-timezone-settings/71793 "2017-01-16T23:27:03Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sharon.c](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharon.c/32/16076_2.png) [@sharon.c](https://discuss.elastic.co/u/sharon.c)\
**Post date:** [January 16, 2017, 11:27pm UTC](https://discuss.elastic.co/t/kibana-timezone-settings/71793/1 "2017-01-16T23:27:03Z")

</div>

I am using logstash 5.1 streaming mysql data to elasticsearch 5.1, kibana 5 and this is my logstash code:

```
input {
  jdbc {
    jdbc_driver_library => "./mysql-connector-java-5.1.36.jar"
    jdbc_driver_class => "com.mysql.jdbc.Driver"
    jdbc_connection_string => "jdbc:mysql://..."
    jdbc_user => "myuser"
    jdbc_password => "mypassword"
    jdbc_fetch_size => 200
    statement => " select * from mytable where datetime >= '2016-12-01 11:00:00' and datetime < '2016-12-01 12:00:00' limit 1"
  }
}
    filter {
          mutate {
                add_field => { "[type]" => "log"}
         }
   }
output {
   stdout {codec => rubydebug}
  elasticsearch {
      hosts => ["xxx:9200"]
      index => "XXXXX" # generate for unexpected messages
      template_name => "summary"
   }
}

```

As you noticed there is a datetime field in my mysql table, and I want the values to be the same in elasticsearch, but when I use logstash to stream the data to elasticsearch, from Kibana interface, I can see the data

The stdout {codec =\> rubydebug} result shows:  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/1d49fe6194048b718fb87622bdae712df69f7ac3.png)  
It means datetime field value is correct.

Also if I use sense to query this document, it shows correct value  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/1b71b94492177dfec397424a20da531e697828db.png)

However, if I use **Kibana discover** to see the doc, the value of datetime field is 5 hours ahead of the time, it also happens in Kibana discover histogram.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/5/5af021a87a111e929f14049d545a0d6f256ee5f2.png)

How can I change the timezone settings of Kibana?

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [January 16, 2017, 11:48pm UTC](https://discuss.elastic.co/t/kibana-timezone-settings/71793/2 "2017-01-16T23:48:47Z")

</div>

You're looking for the [logstash `date` filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html).

In the filter section of your config add this:

```auto
date {
  match => ["datetime", "ISO8601"]
}

```

PS: moving this over to the logstash room

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 17, 2017, 6:40am UTC](https://discuss.elastic.co/t/kibana-timezone-settings/71793/3 "2017-01-17T06:40:01Z")

</div>

> However, if I use Kibana discover to see the doc, the value of datetime field is 5 hours ahead of the time, it also happens in Kibana discover histogram.

That's because Kibana by default adjusts the UTC timestamps in ES to the browser's local time. You can change this behavior via Kibana's advanced settings.

> **[Advanced Settings | Kibana Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/kibana/current/advanced-options.html)**

---

<div class="post-metadata">

**Author:** ![sharon.c](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharon.c/32/16076_2.png) [@sharon.c](https://discuss.elastic.co/u/sharon.c)\
**Post date:** [January 18, 2017, 11:04pm UTC](https://discuss.elastic.co/t/kibana-timezone-settings/71793/4 "2017-01-18T23:04:05Z")

</div>

Thanks for your reply. The setting is already set to browser. And the problem still exists.

Because when I import from mysql using logstash, it recognises the datetime field as UTC, but my DB is using EST Timezone. So I need to tell logstash to acknowledge the field is EST. If not, there is time difference between my DB and elasticsearch.

The following is my logstash script:

```
input {
   stdin {}
  jdbc {
    jdbc_driver_library => "./mysql-connector-java-5.1.36.jar"
    jdbc_driver_class => "com.mysql.jdbc.Driver"
    jdbc_connection_string => "jdbc:mysql://..."
    jdbc_user => "myuser"
    jdbc_password => "mypassword"
    jdbc_fetch_size => 200
    statement => " select * from mytable where datetime >= '2016-12-31 00:00:00' and datetime < '2016-12-31 01:00:00' limit 2"
  }
}

    filter {
      mutate {
            convert => ["datetime", "string"]
     }
        date {
                match => ["datetime", "ISO8601"]
                timezone => "America/Toronto"
                locale => "en"
                target => "@timestamp"
        }

          mutate {
               add_field => { "[type]" => "log"}
              remove_field => ["datetime"]

         }
   }
output {
  stdout {codec => rubydebug}
}

```

This code does not set the time zone as "America/Toronto" as I thought, it is still recognized as UTC

---

<div class="post-metadata">

**Author:** ![sharon.c](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharon.c/32/16076_2.png) [@sharon.c](https://discuss.elastic.co/u/sharon.c)\
**Post date:** [January 19, 2017, 1:21am UTC](https://discuss.elastic.co/t/kibana-timezone-settings/71793/5 "2017-01-19T01:21:43Z")

</div>

I got it, I will convert the date field to UTC from mysql side, then it will solve the problem.

On Mysql side, the date is in ET time zone, I converted it to the UTC, then the problem is solved.  
select CONVERT\_TZ(datetime,'+00:00','+05:00') , field1, field2,... from mytable

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 16, 2017, 1:22am UTC](https://discuss.elastic.co/t/kibana-timezone-settings/71793/6 "2017-02-16T01:22:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
