# Locale automatically being set in date filter

**URL:** <https://discuss.elastic.co/t/locale-automatically-being-set-in-date-filter/41050>\
**Category:** Logstash\
**Created:** [February 5, 2016, 11:30am UTC](https://discuss.elastic.co/t/locale-automatically-being-set-in-date-filter/41050 "2016-02-05T11:30:18Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![punit\_naik1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/punit_naik1/32/7239_2.png) [@punit\_naik1](https://discuss.elastic.co/u/punit_naik1)\
**Post date:** [February 5, 2016, 11:30am UTC](https://discuss.elastic.co/t/locale-automatically-being-set-in-date-filter/41050/1 "2016-02-05T11:30:18Z")

</div>

I have a timestamp in my log and its already in the timezone that I want. But when I apply a date filter to it to convert it into a timestamp, it automatically is converted into my local time which I don't want because it already is and therefore it is converted unnecessarily and gives me wrong timestamp. How do I avoid this?

Please help!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 5, 2016, 12:17pm UTC](https://discuss.elastic.co/t/locale-automatically-being-set-in-date-filter/41050/2 "2016-02-05T12:17:34Z")

</div>

Can you give an example, including your configuration and information about the timezone of all hosts involved?

---

<div class="post-metadata">

**Author:** ![punit\_naik1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/punit_naik1/32/7239_2.png) [@punit\_naik1](https://discuss.elastic.co/u/punit_naik1)\
**Post date:** [February 5, 2016, 12:20pm UTC](https://discuss.elastic.co/t/locale-automatically-being-set-in-date-filter/41050/3 "2016-02-05T12:20:25Z")

</div>

Yes of course. Below is the config file.

```
input{
    file{
        path => ["/home/punit/spark.out"]
        start_position => "beginning"    
        codec => multiline 
                    {
                                pattern => "^%{NUMBER}/%{NUMBER}/%{NUMBER}"
                                negate => true
                                what => "previous"
                        }
        }
}
filter{
    grok{
        match => {"message" => "%{NUMBER:log_year}/%{NUMBER:log_month}/%{NUMBER:log_day} %{TIME:log_time} %{LOGLEVEL:log_level} %{DATA:component}: %{GREEDYDATA:log_message}"}
    }
    mutate{
        add_field => {"log_timestamp" => "%{log_year}-%{log_month}-%{log_day} %{log_time}"}
        rename => {"@timestamp" => "event_timestamp"}
                remove_field => ["@version","message","path","log_year","log_month","log_day","log_time"]
    }
    date{
        match => ["log_timestamp","yy-mm-dd HH:mm:ss"]
        target => "log_timestamp"
    }
}
output {
     stdout { codec => json }
    }

```

Its automatically doing +6:30 to the log timestamp even though I have not specified any timezone or locale.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 5, 2016, 12:23pm UTC](https://discuss.elastic.co/t/locale-automatically-being-set-in-date-filter/41050/4 "2016-02-05T12:23:36Z")

</div>

You didn't provide all information that was asked for. Are you taking into account that the date filter always converts timestamps to UTC?

---

<div class="post-metadata">

**Author:** ![punit\_naik1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/punit_naik1/32/7239_2.png) [@punit\_naik1](https://discuss.elastic.co/u/punit_naik1)\
**Post date:** [February 5, 2016, 12:26pm UTC](https://discuss.elastic.co/t/locale-automatically-being-set-in-date-filter/41050/5 "2016-02-05T12:26:01Z")

</div>

No I didn't know that it converted the timestamp to UTC. And what extra info do I have to provide?

---

<div class="post-metadata">

**Author:** ![punit\_naik1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/punit_naik1/32/7239_2.png) [@punit\_naik1](https://discuss.elastic.co/u/punit_naik1)\
**Post date:** [February 5, 2016, 12:28pm UTC](https://discuss.elastic.co/t/locale-automatically-being-set-in-date-filter/41050/6 "2016-02-05T12:28:06Z")

</div>

I want the time as it is in the log file.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 5, 2016, 12:28pm UTC](https://discuss.elastic.co/t/locale-automatically-being-set-in-date-filter/41050/7 "2016-02-05T12:28:41Z")

</div>

I said

> Can you give an example, including your configuration and information about the timezone of all hosts involved?

and so far I've only seen the configuration. By example I mean what the timestamp looks before the date filter and what it looks like afterwards. The difference you're seeing is probably because of the conversion to UTC.

---

<div class="post-metadata">

**Author:** ![punit\_naik1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/punit_naik1/32/7239_2.png) [@punit\_naik1](https://discuss.elastic.co/u/punit_naik1)\
**Post date:** [February 5, 2016, 12:33pm UTC](https://discuss.elastic.co/t/locale-automatically-being-set-in-date-filter/41050/8 "2016-02-05T12:33:07Z")

</div>

Before date filter:

`16/01/27 16:24:47`

After date filter:

`2016-01-27T10:54:47.000Z`

Here is a line from the file:

`16/01/27 16:24:47 INFO Master: Registered signal handlers for [TERM, HUP, INT]`

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 5, 2016, 12:42pm UTC](https://discuss.elastic.co/t/locale-automatically-being-set-in-date-filter/41050/9 "2016-02-05T12:42:55Z")

</div>

If your local timezone is UTC+6:30 then this is the expected behavior. The date filter always converts to UTC. This is not configurable.

---

<div class="post-metadata">

**Author:** ![punit\_naik1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/punit_naik1/32/7239_2.png) [@punit\_naik1](https://discuss.elastic.co/u/punit_naik1)\
**Post date:** [February 5, 2016, 12:43pm UTC](https://discuss.elastic.co/t/locale-automatically-being-set-in-date-filter/41050/10 "2016-02-05T12:43:53Z")

</div>

Okay thanks a lot @magnusbaeck. I think I was fretting for no reason.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:12am UTC](https://discuss.elastic.co/t/locale-automatically-being-set-in-date-filter/41050/11 "2017-07-06T05:12:53Z")

</div>


