# Logstash changing date received from filebeat

**URL:** <https://discuss.elastic.co/t/logstash-changing-date-received-from-filebeat/137972>\
**Category:** Logstash\
**Created:** [June 29, 2018, 1:28pm UTC](https://discuss.elastic.co/t/logstash-changing-date-received-from-filebeat/137972 "2018-06-29T13:28:35Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kskubala](https://avatars.discourse-cdn.com/v4/letter/k/c5a1d2/32.png) [@kskubala](https://discuss.elastic.co/u/kskubala)\
**Post date:** [June 29, 2018, 1:28pm UTC](https://discuss.elastic.co/t/logstash-changing-date-received-from-filebeat/137972/1 "2018-06-29T13:28:35Z")

</div>

Hi !  
I am using filebeat to send logs to elasticsearch thru logstash. Inside logstash I am using grok to match the pattern where I extract date string.

> ```
> grok {
> match => {"message" => ["%{GREEDYDATA:log_time} \[% ***** (other things...)
> 
> ```

Then I have to map it to date:

> ```
> date{
> match => ["log_time", "YYYY-MM-dd HH:mm:ss.SSSS"]
> target => "log_time"
> }
> 
> ```

But it is changing my date for example from  
2018-03-29 03:00:51.0388 to March 29th 2018, 04:00:51.038  
Adding 1 hour. What is responsible for that ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 29, 2018, 1:57pm UTC](https://discuss.elastic.co/t/logstash-changing-date-received-from-filebeat/137972/2 "2018-06-29T13:57:22Z")

</div>

The date filter converts the parsed timestamp to UTC. Kibana by default adjusts UTC timestamps to the brower's timezone.

---

<div class="post-metadata">

**Author:** ![kskubala](https://avatars.discourse-cdn.com/v4/letter/k/c5a1d2/32.png) [@kskubala](https://discuss.elastic.co/u/kskubala)\
**Post date:** [June 29, 2018, 2:04pm UTC](https://discuss.elastic.co/t/logstash-changing-date-received-from-filebeat/137972/3 "2018-06-29T14:04:36Z")

</div>

Yes, just found that, but in my opinion it is not right. Usually logs are saved to files with date and due to that convertion I have document in elastic that log's date time is not existing in the file.  
Anyway thanks for surprisingly quick answer.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 2, 2018, 7:04am UTC](https://discuss.elastic.co/t/logstash-changing-date-received-from-filebeat/137972/4 "2018-07-02T07:04:52Z")

</div>

> Usually logs are saved to files with date and due to that convertion I have document in elastic that log's date time is not existing in the file.

Why does the timestamp format and timezone matter? The important thing is that it represents the same point in time as in the original log.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 30, 2018, 7:05am UTC](https://discuss.elastic.co/t/logstash-changing-date-received-from-filebeat/137972/5 "2018-07-30T07:05:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
