# Logstash Date and Kibana Issues

**URL:** <https://discuss.elastic.co/t/logstash-date-and-kibana-issues/192817>\
**Category:** Logstash\
**Created:** [July 30, 2019, 4:31am UTC](https://discuss.elastic.co/t/logstash-date-and-kibana-issues/192817 "2019-07-30T04:31:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [July 30, 2019, 4:31am UTC](https://discuss.elastic.co/t/logstash-date-and-kibana-issues/192817/1 "2019-07-30T04:31:57Z")

</div>

Not really sure where this goes but it isn't getting any bites in the Logstash forums so...

I have a field that tracks when a ticket was created, `sys_created_on`. The time is in local timezone, -05:00 currently. I have the following logstash config:

```auto
  date {
    match => ["sys_created_on", "yyyy-MM-dd HH:mm:ss"]
    timezone => "America/Chicago"
  }

```

In Kibana, I am using the `@timestamp` field as the time field. When events come up in Kibana, they show a time that is five hours in the future. When I look at the JSON data, it is showing a timestamp 10 hours in the future. What the hell am I doing wrong??

---

<div class="post-metadata">

**Author:** ![Aaron\_Caldwell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron_caldwell/32/45755_2.png) [@Aaron\_Caldwell](https://discuss.elastic.co/u/Aaron_Caldwell)\
**Post date:** [July 30, 2019, 3:46pm UTC](https://discuss.elastic.co/t/logstash-date-and-kibana-issues/192817/2 "2019-07-30T15:46:18Z")

</div>

Hello,

I do think this belongs in the Logstash forum so I'll move it back over, but I did find this similar issue which may help!

> [@Kibana Timezone settings](https://discuss.elastic.co/t/kibana-timezone-settings/71793):
>
> I am using logstash 5.1 streaming mysql data to elasticsearch 5.1, kibana 5 and this is my logstash code: input { jdbc { jdbc\_driver\_library =\> "./mysql-connector-java-5.1.36.jar" jdbc\_driver\_class =\> "com.mysql.jdbc.Driver" jdbc\_connection\_string =\> "jdbc:mysql://..." jdbc\_user =\> "myuser" jdbc\_password =\> "mypassword" jdbc\_fetch\_size =\> 200 statement =\> " select \* from mytable where datetime \>= '2016-12-01 11:00:00' and datetime \< '2016-12-01 12:00:00' limit 1"…

Regards,  
Aaron

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 30, 2019, 3:53pm UTC](https://discuss.elastic.co/t/logstash-date-and-kibana-issues/192817/3 "2019-07-30T15:53:19Z")

</div>

Is sys\_created\_on a string? Also, what does your input look like? I am wondering if you are fetching from a DB and the input is doing the conversion to the local timezone or something like that.

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [July 30, 2019, 4:14pm UTC](https://discuss.elastic.co/t/logstash-date-and-kibana-issues/192817/4 "2019-07-30T16:14:23Z")

</div>

http\_poller pulls from an API endpoint that delivers the data in a json formatted document. The value is a string in the json and is local time.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 27, 2019, 4:14pm UTC](https://discuss.elastic.co/t/logstash-date-and-kibana-issues/192817/5 "2019-08-27T16:14:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
