# Log Timezone Question

**URL:** <https://discuss.elastic.co/t/log-timezone-question/211160>\
**Category:** Logstash\
**Created:** [December 9, 2019, 4:52pm UTC](https://discuss.elastic.co/t/log-timezone-question/211160 "2019-12-09T16:52:02Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![ElkLogs](https://avatars.discourse-cdn.com/v4/letter/e/a183cd/32.png) [@ElkLogs](https://discuss.elastic.co/u/ElkLogs)\
**Post date:** [December 9, 2019, 4:52pm UTC](https://discuss.elastic.co/t/log-timezone-question/211160/1 "2019-12-09T16:52:02Z")

</div>

I have been searching through the threads, but I haven't been able to fins a solution. Essentially, I have a log source that ships logs in UTC. I need to adjust them for my timezone, but changing the zone in the logstash config hasn't changed it. The logs show up in Kibana with a timestamp that is offset by the exact amount of my timezone. I'm sure it must be something simple.

Version: 7.5

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 9, 2019, 10:48pm UTC](https://discuss.elastic.co/t/log-timezone-question/211160/2 "2019-12-09T22:48:56Z")

</div>

Logs are stored in elasticsearch in UTC, so specify UTC as the timezone in the date filter.

---

<div class="post-metadata">

**Author:** ![ElkLogs](https://avatars.discourse-cdn.com/v4/letter/e/a183cd/32.png) [@ElkLogs](https://discuss.elastic.co/u/ElkLogs)\
**Post date:** [December 10, 2019, 4:51pm UTC](https://discuss.elastic.co/t/log-timezone-question/211160/3 "2019-12-10T16:51:48Z")

</div>

I apologize, I'm new to using ELK. Do you mean use the date filter in the logstash config? Right now, I have the input section as follows:

```
 input {
     syslog {
         timezone => "UTC"
         port => "5514"
         type => "syslog"
         tags => ["OS_SysLog"]
     }
 }

```

If I am correct so far, do I just need to add the following?

```
date {
    timezone => "UTC"
}

```

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 10, 2019, 5:22pm UTC](https://discuss.elastic.co/t/log-timezone-question/211160/4 "2019-12-10T17:22:05Z")

</div>

OK, I misunderstood. If your syslog entries are arriving with a timestamp in UTC then that syslog input should be OK and you would not need a date filter. They would be stored in elasticsearch as UTC and kibana (with the default settings) would translate them into the timezone where kibana runs.

---

<div class="post-metadata">

**Author:** ![ElkLogs](https://avatars.discourse-cdn.com/v4/letter/e/a183cd/32.png) [@ElkLogs](https://discuss.elastic.co/u/ElkLogs)\
**Post date:** [December 10, 2019, 7:13pm UTC](https://discuss.elastic.co/t/log-timezone-question/211160/5 "2019-12-10T19:13:01Z")

</div>

Maybe that's the problem - my device isn't actually sending in UTC. I will verify that again. If it is actually sending in a different time zone, say EST, would the following be what is required?

```auto
date {
    timezone => "America/New_York"
}

```

---

<div class="post-metadata">

**Author:** ![ElkLogs](https://avatars.discourse-cdn.com/v4/letter/e/a183cd/32.png) [@ElkLogs](https://discuss.elastic.co/u/ElkLogs)\
**Post date:** [December 10, 2019, 7:33pm UTC](https://discuss.elastic.co/t/log-timezone-question/211160/6 "2019-12-10T19:33:42Z")

</div>

Ok, making progress. The logs are in fact NOT being sent in UTC. So, should be a simple fix. I just need to build the correct date filter.

The logs come in this format:

> GeneratedTime 2019/12/10 13:20:27

Edit: I previously gave the incorrect format.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 10, 2019, 7:35pm UTC](https://discuss.elastic.co/t/log-timezone-question/211160/7 "2019-12-10T19:35:14Z")

</div>

If the date is in the right format then the syslog filter will parse it and that is where you would set the timezone. There would be no need for a date filter in that case. However in the format you have you will need to use a date filter.

---

<div class="post-metadata">

**Author:** ![ElkLogs](https://avatars.discourse-cdn.com/v4/letter/e/a183cd/32.png) [@ElkLogs](https://discuss.elastic.co/u/ElkLogs)\
**Post date:** [December 10, 2019, 8:41pm UTC](https://discuss.elastic.co/t/log-timezone-question/211160/8 "2019-12-10T20:41:03Z")

</div>

Ok. It sends the date as follows:

> GeneratedTime  
> 2019/12/10 13:20:27

I re-read the docs on the [syslog plugin](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-syslog.html) and saw that logstash will only accept RFC3164, not RFC5424.

I modified my config file as shown below:

```
filter {
    date {
        match => ["GeneratedTime", "yyyy/MM/dd HH:mm:ss"]
        timezone => "America/New_York"	
    }
    {...}
}

```

I rebooted the VM to ensure all services were restarted after my config change, however, the timestamp remains unchanged when displayed in Kibana. I'm still missing something...

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 10, 2019, 9:26pm UTC](https://discuss.elastic.co/t/log-timezone-question/211160/9 "2019-12-10T21:26:14Z")

</div>

By default the date filter sets @timestamp and does not modify the parsed field, so we would expect GeneratedTime to remain a string.

If you use target to tell the date filter to overwrite GeneratedTime then the format in elasticsearch will change, however, since it has already been mapped as a string it will remain a string. But if you start over with an empty index it will be a date.

---

<div class="post-metadata">

**Author:** ![ElkLogs](https://avatars.discourse-cdn.com/v4/letter/e/a183cd/32.png) [@ElkLogs](https://discuss.elastic.co/u/ElkLogs)\
**Post date:** [December 11, 2019, 2:44pm UTC](https://discuss.elastic.co/t/log-timezone-question/211160/10 "2019-12-11T14:44:21Z")

</div>

Ok. More progress. I have my filter config as shown:

```
filter {
    date {
        match => ["GeneratedTime", "yyyy/MM/dd HH:mm:ss"]
        timezone => "America/New_York"
        target => "GeneratedTime"
   }

```

If I set the Time Filter field name to @timestamp on the index pattern, the logs show up in the correct time. However, if I use "GeneratedTime" they do not. Is there something wrong with they way I am using the target?

Also, I have deleted the indexes after each change.

---

<div class="post-metadata">

**Author:** ![ITIC](https://avatars.discourse-cdn.com/v4/letter/i/90ced4/32.png) [@ITIC](https://discuss.elastic.co/u/ITIC)\
**Post date:** [December 12, 2019, 1:56pm UTC](https://discuss.elastic.co/t/log-timezone-question/211160/11 "2019-12-12T13:56:33Z")

</div>

Hi

You need to convert the time to your timezone. This solution might help: [Time in IST for log-rotation - Logstash](https://discuss.elastic.co/t/time-in-ist-for-log-rotation-logstash/211612/2)

Hope this helps

---

<div class="post-metadata">

**Author:** ![ElkLogs](https://avatars.discourse-cdn.com/v4/letter/e/a183cd/32.png) [@ElkLogs](https://discuss.elastic.co/u/ElkLogs)\
**Post date:** [December 12, 2019, 2:42pm UTC](https://discuss.elastic.co/t/log-timezone-question/211160/12 "2019-12-12T14:42:43Z")

</div>

Thank you for you suggestion. However, that doesn't help much in my case as I am not trying to name the files as such. I think what I need to do is overwrite my 'GeneratedTime' field with the corrected time from the same field.

---

<div class="post-metadata">

**Author:** ![ITIC](https://avatars.discourse-cdn.com/v4/letter/i/90ced4/32.png) [@ITIC](https://discuss.elastic.co/u/ITIC)\
**Post date:** [December 13, 2019, 6:53am UTC](https://discuss.elastic.co/t/log-timezone-question/211160/13 "2019-12-13T06:53:33Z")

</div>

Hi

Your case is not the same as the one in the other post, but I still think the ruby filter will do what you need.

Replace `@timestamp` with your `GeneratedTime` and `filename` with a variable of your choice, e.g. `GeneratedTime`, and you will get the time in your time zone. You'll have to play with the format in `...strftime('%Y-%m-%d/%H'))`, but that's it.

Hope this helps

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2020, 6:53am UTC](https://discuss.elastic.co/t/log-timezone-question/211160/14 "2020-01-10T06:53:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
